Because O+ Connect's IPC service does not authenticate clients, external applications can escalate privileges and perform sensitive actions through the IPC channel.
Metrics
Affected Vendors & Products
References
History
Mon, 29 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Oppo
Oppo o+ Connect |
|
| Vendors & Products |
Oppo
Oppo o+ Connect |
Mon, 29 Jun 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 29 Jun 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Because O+ Connect's IPC service does not authenticate clients, external applications can escalate privileges and perform sensitive actions through the IPC channel. | |
| Title | O+ Connect's lack of authentication for IPC channels led to a local privilege escalation vulnerability. | |
| Weaknesses | CWE-266 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: OPPO
Published:
Updated: 2026-06-29T11:53:21.664Z
Reserved: 2026-01-06T06:15:53.765Z
Link: CVE-2026-22078
Updated: 2026-06-29T11:53:16.903Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-29T13:15:03Z