What is CVE-2026-14354?
CVE-2026-14354 is an Insufficiently Protected Credentials (CWE-522) vulnerability that could allow a local privileged attacker to bypass authentication and modify credentials by exploiting weaknesses in stored credential handling, potentially leading to the compromise of managed devices. Mitigation requires applying patches and strictly restricting local access privileges on affected systems.
Azərbaycanca: CVE-2026-14354, kifayət qədər qorunmayan etimadnamələr (CWE-522) zəifliyidir. Bu zəiflik lokal imtiyazlı təcavüzkarın saxlanılan etimadnamələrin idarə edilməsi və qorunmasındakı boşluqlardan istifadə edərək autentifikasiyanı keçməsinə və etimadnamələri icazəsiz dəyişdirməsinə, nəticədə idarə olunan cihazların komprometasiyasına səbəb ola bilər. Təsirə məruz qalan sistemlərdə dərhal yamaqlar tətbiq edilməli və lokal giriş imtiyazları ciddi şəkildə məhdudlaşdırılmalıdır.
Related CVEs
link basis: same weakness class CWE-522
FAQ2
What type of vulnerability is CVE-2026-14354?
CVE-2026-14354 is an Insufficiently Protected Credentials (CWE-522) vulnerability, related to inadequately protected stored credentials.
What actions can an attacker exploiting this vulnerability perform?
A local privileged attacker can bypass authentication and modify credentials, potentially leading to the compromise of managed devices.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.