CVE-2026-27788
Deferred
Deferred - Pending Action
Incorrect Permission Assignment in ServerView Agents for Windows Leads to Privilege Escalation
Publication date: 2026-06-01
Last updated on: 2026-06-01
Assigner: JPCERT/CC
Description
Description
Incorrect permission assignment for critical resource issue exists in ServerView Agents for Windows V11.60.04 and earlier. If this vulnerability is exploited, a local authenticated attacker who can log in to the server where the affected product is installed may obtain SYSTEM privilege.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| unify | serverview_agents | to 11.60.04 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-732 | The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. |