CVE-2026-37525

7.8

ABB · Multiple Products (AGL app-framework-binder)

A privilege escalation vulnerability in AGL app-framework-binder (afb-daemon) allows local attackers to execute arbitrary APIs with null credentials.

Executive summary

A privilege escalation vulnerability in the AGL app-framework-binder affects multiple ABB products up to version 19.90.0, allowing local users to bypass security controls and execute arbitrary APIs with null credentials.

Vulnerability

This privilege escalation flaw involves improper credential handling within the supervision Do command in src/afb-supervision.c, where low-privileged local attackers can trigger arbitrary API calls with null credentials, enabling them to bypass authorization checks.

Business impact

A successful exploit allows a local attacker to escalate privileges and execute authorized API calls that fail open when receiving null credentials. This compromises the integrity and confidentiality of the underlying automotive or embedded system, potentially leading to unauthorized control functions or data access. The CVSS score of 7.8 indicates high severity, reflecting substantial potential impact on system security despite requiring low privileges.

Remediation

Immediate Action: Apply vendor security updates immediately as provided by ABB or the Automotive Grade Linux project.

Proactive Monitoring: Monitor system logs for anomalous API execution patterns and unexpected supervisor command invocations.

Compensating Controls: Restrict local user access and shell privileges on the affected device to minimize the likelihood of an attacker establishing local execution capability.

Exploitation status

Public Exploit Available: No — no confirmed public exploit is currently tracked in our primary data sources.

Analyst recommendation

Given the high severity and potential for total technical impact on affected systems, administrators must prioritize applying vendor patches as soon as they become available. Restricting local access provides a critical layer of defense while awaiting remediation.

More ABB CVEs

Sources