SB2026090238 - Multiple vulnerabilities in ShizenBox2



SB2026090238 - Multiple vulnerabilities in ShizenBox2

Published: September 2, 2026

Security Bulletin ID SB2026090238
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Medium 50% Low 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 vulnerabilities.


1) Improper Physical Access Control (CVE-ID: CVE-2026-80253)

CWE-ID: CWE-1263 - Improper Physical Access Control

CVSSv4: 7 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper physical access control. An attacker with physical access can execute bootloader commands without authentication.


2) Authorization bypass through user-controlled key (CVE-ID: CVE-2026-80254)

CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authorization checks.

The vulnerability exists due to authorization bypass through user-controlled key. A remote user can change the other user's password.


Remediation

Install update from vendor's website.