Sceawere

Vulnerability Detail

CVE-2026-28165UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthenticated Privilege Escalation in Digits

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
3h ago
Vendor
UnitedOver, LLC
Product
Digits
Attack Type
CWE-266 Incorrect Privilege Assignment
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Privilege Escalation in Digits <= 9.2 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-08-24T12:16:50.600Z",
  "pubdate": "2026-08-24T12:16:50.600Z",
  "executiveSummary": "An unauthenticated privilege escalation vulnerability has been identified in Digits versions 9.2 and below. This security flaw allows remote, unauthenticated threat actors to bypass standard access controls and elevate their privilege level within the targeted application without requiring prior interaction or valid credentials. The primary impact of this vulnerability involves unauthorized access to administrative functions, sensitive data exposure, and potential total system compromise depending on the underlying implementation. The risk implications are severe, as unauthorized entities can manipulate system parameters, execute privileged operations, and subvert the intended security boundary enforced by the application architecture. Attacker capabilities include full interaction with restricted administrative endpoints and manipulation of user states without authentication. Exploitation requirements are minimal, relying solely on network accessibility to the vulnerable Digits <= 9.2 instance and the ability to interact with the exposed insecure component. Organizations running affected versions face significant exposure to malicious actors seeking to leverage broken access control mechanisms for lateral movement or persistence.",
  "technicalDetails": "The vulnerability resides within the access control and authorization enforcement mechanisms of Digits versions 9.2 and below, specifically involving the handling of unauthenticated requests to privileged functional components. The root cause stems from a failure in the application logic to properly validate the authentication state and privilege level of incoming requests before executing sensitive operations or granting administrative capabilities. Attack flow begins when an unauthenticated adversary crafts and transmits a malicious HTTP request targeting vulnerable endpoints within the application. Because the affected component fails to enforce proper session validation or cryptographic verification of user roles, the system processes the request as if it originated from a legitimately authenticated privileged user. Exploitation method relies on bypassing authorization checks by directly invoking functions intended solely for higher privilege tiers. Network exposure is critical, as the vulnerable functions are typically accessible over standard network protocols without requiring pre-existing credentials. Payload behavior involves tricking the core application logic into elevating the attacker context, thereby granting unauthorized administrative privileges. Post-exploitation impact encompasses full administrative control over the affected Digits environment, allowing the adversary to modify configurations, compromise additional user accounts, extract sensitive internal data, or deploy further malicious payloads. The vulnerability exhibits characteristics of broken object level authorization and missing function-level access control within the affected codebase."
}
CVE-2026-28165: Unauthenticated Privilege Escalation in Digits (CRITICAL Severity, CVSS: 9.8) - Sceawere