LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →

CVE-2026-0110 - Vulnerability Analysis

CriticalCVSS: 9.8

Last Updated: March 11, 2026

Unknown - Privilege Escalation

Published: March 10, 2026Updated: March 11, 2026Remote Exploitable

Overview

Unknown vendor product contains a privilege escalation caused by memory corruption in MM_DATA_IND of cn_NrSmMsgHdlrFromMM.cpp, letting remote attackers escalate privileges without additional execution rights, exploit requires no user interaction.

Severity & Score

Severity: Critical
CVSS Score: 9.8

Impact

Remote attackers can escalate privileges without needing additional execution rights or user interaction.

Mitigation

Update to the latest version or apply vendor patches addressing memory corruption.

Details

CVE ID
CVE-2026-0110
Severity
Critical
CVSS Score
9.8
Type
undefined
Status
confirmed

CWE

  • CWE-120

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H