CVE-2026-20467
Received Received - Intake

Privilege Escalation in Apusys Due to Missing Bounds Check

Vulnerability report for CVE-2026-20467, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-03

Last updated on: 2026-08-03

Assigner: MediaTek, Inc.

Description

In apusys, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: AUTO00837766; Issue ID: MSV-6767.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-03
Last Modified
2026-08-03
Generated
2026-08-03
AI Q&A
2026-08-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-749 The product provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in apusys allows privilege escalation due to a missing bounds check. If an attacker already has System privilege, they could exploit this to gain higher privileges without needing user interaction.

Impact Analysis

If you are using apusys, an attacker with System privilege could exploit this to escalate their privileges further, potentially gaining full control over the system.

Compliance Impact

This vulnerability allows local privilege escalation to System level if an attacker already has System privilege, which could potentially bypass security controls. This may impact compliance by weakening access controls and data protection measures required under standards like GDPR and HIPAA.

Mitigation Strategies

Apply the patch identified as AUTO00837766 to address the missing bounds check in apusys. Ensure the System privilege is not granted to untrusted users to prevent potential local privilege escalation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-20467. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart