CVE-2026-37526Disclosure(linuxfoundation / automotive_grade_linux)

LOWCVSS 7.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

AGL app-framework-binder (afb-daemon) through v19.90.0 allows any local process to execute privileged supervision commands (Exit, Do, Sclose, Config, Trace, Debug, Token, slist) without authentication via the abstract Unix socket @urn:AGL:afs:supervision:socket. The on_supervision_call function in src/afb-supervision.c dispatches all 8 commands without any credential verification. The abstract socket has no DAC protection, as acknowledged in the official CAUTION comment in src/afs-supervision.h. This allows a low-privileged local process to kill the daemon (DoS via Exit command), execute arbitrary API calls (via Do command), close arbitrary user sessions (via Sclose command), or leak the entire global configuration (via Config command). The vulnerability was introduced in commit b8c9d5de384efcfa53ebdb3f0053d7b3723777e1 on 2017-06-29.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • automotive_grade_linux

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Products
automotive_grade_linux

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-01: 2Technical Details · 2026-05-01: 205-01
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-37526 Unauthenticated Privileged Command Execution in AGL app-framework-binder Through v19.90.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-37526

    Post summary

    This text announces CVE-2026-37526, an unauthenticated privileged command execution vulnerability in AGL app-framework-binder v19.90.0, with no PoC, exploit code, or active exploitation evidence reported.

    0000049
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-37526 AGL app-framework-binder (afb-daemon) through v19.90.0 allows any local process to execute privileged supervision commands (Exit, Do, Sclose, Config, Trace, Debug, To… https://www.cve.org/CVERecord?id=CVE-2026-37526

    Post summary

    The text announces CVE-2026-37526 as a local privilege escalation in the AGL app-framework-binder, allowing local processes to run privileged supervision commands.

    00000124
    57.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxfoundationautomotive_grade_linux---

Explore more