🔐 CVE Alert

CVE-2026-14551

HIGH 8.8

Local Privilege Escalation in servereye client (sensorhub)

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

The servereye client (also known as sensorhub, technically ClientAgentContainerService) versions 20.15 and earlier are vulnerable to Local Privilege Escalation. The high-privileged service SE3Recovery (EmergencyRecoveryService.exe), running as SYSTEM, periodically monitors the directory %ProgramData%\ServerEye3\update\ for a trigger file named "update_available". Due to insufficient access restrictions on this directory, a local standard user can create the trigger file and provide a path to a directory containing malicious JSON instructions. The service subsequently executes the utility UpdaterAction.exe with SYSTEM privileges, which parses the instructions and performs an unvalidated file copy from a user-controlled source to a protected system destination (e.g., overwriting a service binary). This leads to full system compromise as the service automatically restarts the overwritten binary with SYSTEM privileges.

CWE CWE-379 CWE-269 CWE-73
Vendor servereye gmbh
Product servereye windows agent (sensorhub)
Published Jul 22, 2026
Stay Ahead of the Next One

Get instant alerts for servereye gmbh servereye windows agent (sensorhub)

Be the first to know when new high vulnerabilities affecting servereye gmbh servereye windows agent (sensorhub) are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

servereye GmbH / servereye Windows Agent (Sensorhub)
0 ≤ 20.15

References

NVD ↗ CVE.org ↗ EPSS Data ↗
servereye.de: https://www.servereye.de/security-bulletins/2026-001/

Credits

Janik Wehrli of InfoGuard Labs