CVE-2026-23648

7.8

Glory · RBG-100

Glory RBG-100 systems contain insecure file permissions on root-executed binaries, allowing local unprivileged users to achieve arbitrary command execution with root-level privileges.

Executive summary

A high-severity local privilege escalation vulnerability exists in Glory RBG-100 recycler systems due to insecure binary permissions.

Vulnerability

The vulnerability is caused by CWE-732, where several system binaries executed by the root user are writable and executable by unprivileged local users. An attacker with existing local access can modify these files to escalate their privileges to root.

Business impact

This flaw poses a significant risk to the integrity and confidentiality of the recycler system, as a successful exploit allows a local attacker to gain full control over the underlying operating system. Given the CVSS score of 7.8, this represents a high-risk scenario where unauthorized administrative access can lead to total system compromise, potential financial data theft, or disruption of cash handling operations.

Remediation

Immediate Action: Contact Glory Global Solutions support immediately to determine the availability of security patches or configuration hardening guides for the ISPK-08 component.

Proactive Monitoring: Monitor system logs for unauthorized modifications to binaries in sensitive directories and track unexpected execution of commands by low-privilege service accounts.

Compensating Controls: Implement strict physical and logical access controls to prevent unauthorized users from gaining local terminal access to the affected hardware.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability is critical for environments where local access to the RBG-100 system is possible. Administrators must prioritize limiting system access to trusted personnel only and coordinate with the vendor to deploy necessary updates as soon as they are made available to mitigate the risk of local privilege escalation.

Sources

Originally found and disclosed by Victor A. Morales, Senior Pentester Team Leader, GM Sectec, Corp., Omar Crespo, Pentester, GM Sectec, Corp., with VulnCheck (coordinator), per the CVE Program record.