CVE-2026-23648Disclosure

LOWCVSS 8.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Glory RBG-100 recycler systems using the ISPK-08 software component contain multiple system binaries with overly permissive file permissions. Several binaries executed by the root user are writable and executable by unprivileged local users. An attacker with local access can replace or modify these binaries to execute arbitrary commands with root privileges, enabling local privilege escalation.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-732

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 2 mentions (2026-02-17); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-02-17: 2Mentions · 2026-02-18: 1Mentions · 2026-02-22: 1Technical Details · 2026-02-17: 2Technical Details · 2026-02-22: 102-1702-1802-22
Signal classification1 categories
Disclosure
4100.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-172
Disclosure2
2026-02-181
Disclosure1
2026-02-221
Disclosure1
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-23648 Glory RBG-100 recycler systems using the ISPK-08 software component contain multiple system binaries with overly permissive file permissions. Several binaries execute… https://www.cve.org/CVERecord?id=CVE-2026-23648

    Post summary

    The post discloses a CVE (2026‑23648) affecting Glory RBG‑100 recycler systems, noting that multiple binaries have overly permissive file permissions, which could lead to privilege escalation, but no exploit, PoC, or patch is discussed.

    00011336
    56.4K followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-23648 - Glory Global Solutions - RBG-100 - https://www.redpacketsecurity.com/cve-alert-cve-2026-23648-glory-global-solutions-rbg-100/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-23648 #glory-global-solutions #rbg-100

    Post summary

    A short CVE alert linking to a web page about CVE‑2026‑23648 for Glory Global Solutions' RBG‑100 is shared, with no additional technical, exploitation, or patch information provided.

    10000112
    3.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-23648 Local Privilege Escalation in Glory RBG-100 Recycler Systems via ... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-23648 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    A new local privilege escalation vulnerability (CVE-2026-23648) has been disclosed for Glory RBG-100 Recycler Systems, with details available via the provided link.

    0001033
    4.0K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-23648 (CVSS:8.5, HIGH) is Awaiting Analysis. Glory RBG-100 recycler systems using the ISPK-08 software component contain multiple system binaries with overly permiss..https://nvd.nist.gov/vuln/detail/CVE-2026-23648 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    A new high‑severity vulnerability (CVE‑2026‑23648) affecting Glory RBG‑100 recycler systems has been identified, with CVSS score and affected binaries noted, but no PoC, exploit, or patch information is provided.

    0000042
    171 followersView on X

Explore more