On a Cryptobox platform where administrator segregation based on entities is used, some vulnerabilities in Ercom Cryptobox administration console allows an authenticated entity administrator with knowledge to elevate his account to global administrator.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
Upgrade to version 4.40.x.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://info.cryptobox.com/doc/v4.40/4.40.en/ |
|
History
Wed, 04 Feb 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | On a Cryptobox platform where administrator segregation based on entities is used, some vulnerabilities in Ercom Cryptobox administration console allows an authenticated entity administrator with knowledge to elevate his account to global administrator. | |
| Title | Privilege Elevation in Ercom Cryptobox administration console | |
| Weaknesses | CWE-1220 CWE-79 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: THA-PSIRT
Published:
Updated: 2026-02-04T10:42:14.626Z
Reserved: 2026-01-13T09:32:07.338Z
Link: CVE-2026-0873
No data.
Status : Received
Published: 2026-02-04T11:16:02.797
Modified: 2026-02-04T11:16:02.797
Link: CVE-2026-0873
No data.
OpenCVE Enrichment
No data.