Vulnary
← back to the feed
Critical· 9.3

CVE-2026-21102

A critical flaw in DualDAR software allows a local user with elevated privileges to run arbitrary code as the system’s root user. The vulnerability is a use‑after‑free bug that can be triggered by a privileged attacker on the same machine. It is not publicly exploitable yet, but it could let an attacker take full control of the affected system.

publishedSep 9, 2026
last modifiedSep 11, 2026
sourcesNVD
severity · cvss
9.3
critical · how bad it is
exploitation · epss
<1%
2th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Oct 24, 2026

No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.

01

Who is affected

DualDAR software versions prior to the SMR Sep‑2026 Release 1.

02

Real-world impact

An attacker who can run programs on the affected machine could exploit the flaw to execute any code they choose with root privileges, effectively taking over the entire system.

03

Why this severity

The CVSS score of 9.3 reflects that the flaw is local, requires high privileges to exploit, and grants the attacker full control over the system. The vector shows that the attacker needs local access and can achieve high impact on confidentiality, integrity, and availability.

04

What to do about it

no official fix yet

No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.

No fix documented in sources

05

Timeline

06

How it’s attacked

Attack vectorLocal
Attack complexityLow
Attack requirementsNone
Privileges requiredHigh
User interactionNone needed
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
CVE-2026-21102: A critical flaw in DualDAR software allows a local user with elevated · Vulnary