Skip to main content

Privilege Escalation via Binary Planting in Genetec-provided RabbitMQ

The RabbitMQ installation on multiple Genetec products created a directory with weak permissions, which allowed any authenticated user to inject arbitrary code that was then executed by the service. A local attacker could exploit this vulnerability in combination with Rotten Potato or similar potato-family privilege escalation techniques to achieve SYSTEM-level privileges on the affected system. CVE-2026-25112

Read the full advisory here

Share this article

Dive deeper

  • Service Focus

Cybersecurity

  • Magazine

Digital security magazine 18th Edition

  • Magazine

Digital security magazine 19th Edition