What is CVE-2026-48098?
CVE-2026-48098 is a critical privilege escalation vulnerability in the NexTor IP Changer tool. Versions before 2.0.0 execute `sudo` commands with `shell=True` directly in application logic, which on environments with passwordless sudo (`NOPASSWD`) can lead to full system compromise. Immediate update and permission restrictions are required.
Azərbaycanca: CVE-2026-48098 NexTor IP Changer alətində kritik imtiyaz yüksəltmə zəifliyidir. Versiyalar 2.0.0-dən əvvəl tətbiq məntiqində `sudo` əmrlərini birbaşa `shell=True` ilə icra edir ki, bu da parolsuz sudo (`NOPASSWD`) konfiqurasiyalı mühitlərdə sistem komprometinə səbəb ola bilər. Dərhal son versiyaya yenilənməli və icazələr məhdudlaşdırılmalıdır.
Related CVEs
link basis: same weakness class CWE-269
FAQ2
Which versions of NexTor IP Changer are affected by CVE-2026-48098?
This vulnerability affects NexTor IP Changer versions prior to 2.0.0.
Under what condition can CVE-2026-48098 lead to full system compromise?
On environments with passwordless sudo (`NOPASSWD`), this vulnerability can lead to full system compromise.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.