CVE-2023-26603
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
26/04/2024
Last modified:
15/04/2026
Description
JumpCloud Agent before 1.178.0 Creates a Temporary File in a Directory with Insecure Permissions. This allows privilege escalation to SYSTEM via a repair action in the installer.
Impact
Base Score 3.x
5.90
Severity 3.x
MEDIUM
References to Advisories, Solutions, and Tools
- https://community.jumpcloud.com/t5/jumpcloud-product-news/bd-p/releases
- https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2024/MNDT-2024-0003.md
- https://community.jumpcloud.com/t5/jumpcloud-product-news/bd-p/releases
- https://github.com/mandiant/Vulnerability-Disclosures/blob/master/2024/MNDT-2024-0003.md



