


Perceptive Security
SOC/SIEM Consultancy

The affected Ebyte
product does not provide separation between limited and administrative
management functions. A low privileged authenticated attacker could…
Published:
31 August 2026 at 00:00:00
Alert date:
31 August 2026 at 19:01:35
Source:
nvd.nist.gov
Mobile & IoT, Critical Infrastructure, Identity & Access
CVE-2026-77966 affects an Ebyte product that fails to properly separate limited user and administrative management functions. A low-privileged authenticated attacker can access security-sensitive configuration functions without proper authorization. The vulnerability allows modification of device settings that impact confidentiality, integrity, or availability. This is classified as an improper access control / privilege escalation issue in an OT/IoT device. The vulnerability was reported via NVD and has an associated CISA ICS advisory (ICSA-26-237-06). The issue poses a significant risk in operational technology environments where device integrity is critical. No exploit code is publicly referenced, but the low privilege requirement lowers the bar for exploitation.
Technical details
Mitigation steps:
Affected products:
Ebyte
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-77966
https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-06.json
https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-06
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
