SB2026090238 - Multiple vulnerabilities in ShizenBox2
Published: September 2, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 vulnerabilities.
1) Improper Physical Access Control (CVE-ID: CVE-2026-80253)
CWE-ID: CWE-1263 - Improper Physical Access Control
CVSSv4: 7 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper physical access control. An attacker with physical access can execute bootloader commands without authentication.
2) Authorization bypass through user-controlled key (CVE-ID: CVE-2026-80254)
CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to authorization bypass through user-controlled key. A remote user can change the other user's password.
Remediation
Install update from vendor's website.