← Vulnerability feed

Vulnerability record · CVE-2024-36046 · published 27 February 2025

CVE-2024-36046: Infoblox nios improper privilege management vulnerability

Infoblox · Nios

Infoblox NIOS through 8.6.4 executes with more privileges than required.

9.8 CVSS 3.1 Critical EPSS 0.41% · top 67.4% CWE-269 · Improper privilege management
9.8CVSS 3.1 base score
0.41%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Infoblox NIOS through 8.6.4 executes with more privileges than required.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-36046 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-36047Infoblox nios improper input validation vulnerabilityInfoblox NIOS through 8.6.4 and 9.x through 9.0.3 has Improper Input Validation.EPSS 0.44%9.8CVE-2024-37566Infoblox nios improper access control vulnerabilityInfoblox NIOS through 8.6.4 has Improper Authentication for Grids.EPSS 0.46%9.1CVE-2024-37567Infoblox nios improper access control vulnerabilityInfoblox NIOS through 8.6.4 has Improper Access Control for Grids.EPSS 0.35%8.8CVE-2025-61880Infoblox nios deserialization of untrusted data vulnerabilityIn Infoblox NIOS through 9.0.7, insecure deserialization can result in remote code execution.EPSS 0.59%8.8CVE-2023-37249Infoblox nios os command injection vulnerabilityInfoblox NIOS through 8.5.1 has a faulty component that accepts malicious input without sanitization, resulting in shell access.EPSS 0.73%7.7CVE-2025-61879Infoblox nios improper access control vulnerabilityIn Infoblox NIOS through 9.0.7, a High-Privileged User Can Trigger an Arbitrary File Write via the Account Creation Mechanism.EPSS 0.27%6.7CVE-2018-10239Infoblox nios permissions and access controls vulnerabilityA privilege escalation vulnerability in the "support access" feature on Infoblox NIOS 6.8 through 8.4.1 could allow a locally authenticated administr…EPSS 0.38%6.5CVE-2020-15303Infoblox nios vulnerabilityInfoblox NIOS before 8.5.2 allows entity expansion during an XML upload operation, a related issue to CVE-2003-1564.EPSS 0.86%

Source: NIST National Vulnerability Database (record CVE-2024-36046), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.