PatchSiren

Phoenix Contact CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Phoenix Contact CVE published 2026-07-30

CVE-2026-44106

A CVE record was published for a privilege escalation vulnerability in an init-script for user-applications. The vulnerability allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise. This CVE record was published on 2026-07-30T07:16:59.027Z and was last modified on 2026-07-31T23:17:24.103Z. The vulnerability is a high severity issue with a CVSS score [truncated]

HIGH Phoenix Contact CVE published 2026-07-30

CVE-2026-44096

A privilege escalation vulnerability in udhcpc allows a local user 'charx-web' to execute arbitrary commands as root, resulting in full system compromise. This high-severity vulnerability, with a CVSS score of 8.5, poses a significant risk to systems using udhcpc. The vulnerability's impact is exacerbated by its local exploitation vector, which could allow an attacker to gain elevated privileges and execu [truncated]

HIGH Phoenix Contact CVE published 2026-05-27

CVE-2025-41670

A local privilege escalation vulnerability exists where a low-privileged user can manipulate configuration or application files in user-writable filesystem locations to influence the behavior of a privileged system service. The service processes data from insufficiently protected locations, and because it runs with elevated privileges, successful exploitation may result in local privilege escalation. The [truncated]