CVE-2024-39755: Veertu Anka Build Cloud

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

A privilege escalation vulnerability exists in the node update functionality of Veertu Anka Build 1.42.0. A specially crafted PKG file can lead to execute priviledged operation. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.

Affected products

  • Veertu Anka Build Cloud: version 1.42.0 only

Published 2024-10-03. Last modified 2026-06-17.