CVE-2026-40001
Awaiting Analysis
Awaiting Analysis - Queue
Local Privilege Escalation in ZTE Cloud Computer Client
Publication date: 2026-05-06
Last updated on: 2026-05-06
Assigner: ZTE Corporation
Description
Description
There is a local privilege escalation vulnerability in the ZTE PROCESS Guard service of the cloud computer client, which may allow local arbitrary code execution, privilege escalation and path traversal bypass.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| zte | process_guard | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-269 | The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor. |