What is CVE-2026-67609?
CVE-2026-67609 is a privilege escalation vulnerability in Telenia Software TVox versions 26.5.3 and prior 26.x, as well as 24.9.21 and prior 24.x. It allows attackers with access to the `apache` account to execute arbitrary commands as root by exploiting an insecure sudoers configuration in `/etc/sudoers.d/tele`. Affected users should upgrade TVox to the latest patched version.
Azərbaycanca: CVE-2026-67609, Telenia Software TVox-un 26.5.3 və əvvəlki versiyalarında, həmçinin 24.9.21 və əvvəlki versiyalarında mövcud olan imtiyaz yüksəltmə zəifliyidir. Bu boşluq `apache` hesabına giriş əldə edən hücumçulara `/etc/sudoers.d/tele` faylındakı zəif sudoers konfiqurasiyasından istifadə edərək root imtiyazları ilə komandalar icra etməyə imkan verir. Təsirə məruz qalan istifadəçilər TVox proqramını ən son versiyaya yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-269
FAQ2
Which account must an attacker gain access to in order to successfully exploit CVE-2026-67609?
The attacker must gain access to the `apache` account.
Which versions of Telenia Software TVox are affected by CVE-2026-67609?
This vulnerability affects versions 26.5.3 and prior 26.x, as well as 24.9.21 and prior 24.x.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.