CVE Explorer
CVE-2026-25702
A Improper Access Control vulnerability in the kernel of SUSE SUSE Linux Enterprise Server 12 SP5 breaks nftables, causing firewall rules applied via nftables to not be effective.This issue affects SUSE Linux Enterprise Server: from 9e6d9d4601768c75fdb0bad3fbbe636e748939c2 before 9c294edb7085fb91650bc12233495a8974c5ff2d.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","packageName":"kernel","product":"SUSE Linux Enterprise Server","vendor":"SUSE","versions":[{"lessThan":"9c294edb7085fb91650bc12233495a8974c5ff2d","status":"affected","version":"9e6d9d4601768c75fdb0bad3fbbe636e748939c2","versionType":"git"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:c78bbc19cce178aa5cd9ad0c88c15d72d680cd093f8c3258451af5231a7f5858 · sha256:92d9b3328061b525… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":7.3,"baseSeverity":"HIGH","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:c78bbc19cce178aa5cd9ad0c88c15d72d680cd093f8c3258451af5231a7f5858 · sha256:92d9b3328061b525… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-284","description":"CWE-284: Improper Access Control","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:c78bbc19cce178aa5cd9ad0c88c15d72d680cd093f8c3258451af5231a7f5858 · sha256:92d9b3328061b525… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"url":"https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-25702"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:c78bbc19cce178aa5cd9ad0c88c15d72d680cd093f8c3258451af5231a7f5858 · sha256:92d9b3328061b525… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.