CVE-2026-27668: Siemens Ruggedcom Crossbow Secure Access Manager Primary Sam-P
High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.
A vulnerability has been identified in RUGGEDCOM CROSSBOW Secure Access Manager Primary (SAM-P) (All versions < V5.8). User Administrators are allowed to administer groups they belong to. This could allow an authenticated User Administrator to escalate their own privileges and grant themselves access to any device group at any access level.
Affected products
- Siemens Ruggedcom Crossbow Secure Access Manager Primary Sam-P: before V5.8 (fixed in V5.8)
Published 2026-04-14. Last modified 2026-06-17.