CVSS
No CVSS.
c
aptive browser, a dedicated Chrome instance to log into captive portals without messing with DNS settings. In 25.05 and earlier, when programs.captive-browser is enabled, any user of the system can run arbitrary commands with the CAP_NET_RAW capability (binding to privileged ports, spoofing localhost traffic from privileged services...). This vulnerability is fixed in 25.11 and 26.05.
References
Configurations
No configuration.
History
09 Feb 2026, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-09 21:15
Updated : 2026-02-09 21:55
NVD link : CVE-2026-25740
Mitre link : CVE-2026-25740
CVE.ORG link : CVE-2026-25740
JSON object : View
Products Affected
No product.
CWE
CWE-250
Execution with Unnecessary Privileges