Moxa CVE-2026-46333: ssh-keysign-pwn Vulnerability in Linux Kernel
MonitorCVSS 7.1MPSA-267410Jul 24, 2026
Moxa
Summary
CVE-2026-46333 is a local privilege escalation vulnerability in the Linux kernel's ptrace mechanism (ptrace: slightly saner get_dumpable() logic). An attacker with a regular user account can exploit improper privilege management (CWE-269) to execute arbitrary commands with root privileges, allowing full system compromise. The vulnerability does not require remote network access and cannot be exploited by unauthenticated users, but poses significant risk to any system where user accounts exist.
What this means
What could happen
An attacker with a regular user account on a system running an affected Linux kernel can escalate privileges to root and execute arbitrary commands, potentially gaining complete control of the device and any connected industrial systems.
Who's at risk
Water authorities and electric utilities should assess all Linux-based devices, including SCADA servers, historian systems, operator workstations, and any Moxa industrial networking equipment running Linux kernels. Any device where an operator or contractor might have local access is at risk.
How it could be exploited
An attacker with local user access exploits improper privilege management in the kernel's ptrace mechanism to bypass access controls and gain root-level command execution. This could affect any ICS device or operator workstation running the vulnerable kernel versions.
Prerequisites
- Local user account on the affected system
- Access to a shell or command execution interface
- Vulnerable Linux kernel version installed
Local exploitation onlyLow complexity attackNo authentication bypass required once user account existsAffects sensitive systems (root-level access)Privilege escalation to root
Exploitability
Some exploitation risk — EPSS score 1.5%
Metasploit module available — weaponized exploitView module ↗
Public Proof-of-Concept (PoC) on GitHub (4 repositories)
Affected products (1)
ProductAffected VersionsFix Status
Linux KernelAll versionsNo fix yet
Remediation & Mitigation
0/4
Do now
0/2HARDENINGRestrict local user account creation to only necessary personnel; audit and remove unused or test accounts from all systems
HARDENINGImplement host-based access controls to limit which users can execute privileged commands or access sensitive processes
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXContact Moxa or your Linux distribution vendor for patched kernel versions and apply the security update immediately through your normal patch management process
Long-term hardening
0/1HARDENINGMonitor system logs for privilege escalation attempts and unusual root-level process execution
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/88adf122-2b91-4696-84a6-95a4f96981cdGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.