CVE-2025-57489
Incorrect access control in the SDAgent component of Shirt Pocket SuperDuper! v3.10 allows attackers to escalate privileges to root due to t
CVSS
8.1
High
EPSS
0.3%
p22
KEV
—
Exploit Today
7
0-100
Published: Dec 1, 2025 · Last modified: Jul 5, 2026 · CWE-284
0.3%EPSS · 30 days0.3%
2026-08-112026-09-07
Incorrect access control in the SDAgent component of Shirt Pocket SuperDuper! v3.10 allows attackers to escalate privileges to root due to the improper use of a setuid binary.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-196255.3 MED—
———When a Quarkus application has multiple endpoints secured by individual OIDC provider tenants, such as "/oidc-provider1" that is secured by the OIDC Provider 1 and "/oidc-provider2" that is secured by the OIDC Provider 2, and an optional token introspection cache is also enabled, then a valid token issued by the OIDC Provider 1 that can be used to access "/oidc-provider1" can also be used to access "/oidc-provider2" that is secured by another OIDC Provider 2.7hCVE-2026-759987.5 HIG—
———ColdFusion is affected by an Improper Access Control vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction.7hCVE-2026-866725.3 MED—
———A vulnerability has been found in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected is an unknown function of the file example.7z of the component Backup Handler. The manipulation leads to information disclosure. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.10hCVE-2026-819637.8 HIG—
———Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.9hCVE-2026-774878.8 HIG—
———Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.8hCVE-2026-730288.8 HIG—
———Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.10h