CVE-2026-0011
published 2026-03-02CVE-2026-0011: In enableSystemPackageLPw of Settings.java, there is a possible way to prevent location access from working due to a logic error in the code. This could lead…
PriorityP344high8.4CVSS 3.1
AVLACLPRNUINSUCHIHAH
EPSS
0.11%
1.6th percentile
In enableSystemPackageLPw of Settings.java, there is a possible way to prevent location access from working due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | frameworks_base | >= 14:0 < 14:2026-03-01 | 14:2026-03-01 |
| platform | frameworks_base | >= 15:0 < 15:2026-03-01 | 15:2026-03-01 |
| platform | frameworks_base | >= 16-qpr2-next:0 < 16-qpr2-next:2026-03-01 | 16-qpr2-next:2026-03-01 |
| platform | frameworks_base | >= 16-qpr2:0 < 16-qpr2:2026-03-01 | 16-qpr2:2026-03-01 |
| platform | frameworks_base | >= 16:0 < 16:2026-03-01 | 16:2026-03-01 |
CVSS provenance
nvdv3.18.4HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xwh6-73x9-c38w: In enableSystemPackageLPw of Settings
ghsa_unreviewed·2026-03-02
CVE-2026-0011 [HIGH] CWE-693 GHSA-xwh6-73x9-c38w: In enableSystemPackageLPw of Settings
In enableSystemPackageLPw of Settings.java, there is a possible way to prevent location access from working due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
OSV
CVE-2026-0011: In enableSystemPackageLPw of Settings
osv·2026-03-01
CVE-2026-0011 CVE-2026-0011: In enableSystemPackageLPw of Settings
In enableSystemPackageLPw of Settings.java, there is a possible way to prevent location access from working due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Red Hat
vim: NFA regex engine NULL pointer dereference
vendor_redhat·2026-03-12·CVSS 5.3
CVE-2026-32249 [MEDIUM] CWE-476 vim: NFA regex engine NULL pointer dereference
vim: NFA regex engine NULL pointer dereference
Vim is an open source, command line text editor. From 9.1.0011 to before 9.2.0137, Vim's NFA regex compiler, when encountering a collection containing a combining character as the endpoint of a character range (e.g. [0-0\u05bb]), incorrectly emits the composing bytes of that character as separate NFA states. This corrupts the NFA postfix stack, resulting in NFA_START_COLL having a NULL out1 pointer. When nfa_max_width() subsequently traverses the compiled NFA to estimate match width for the look-behind assertion, it dereferences state->out1->out without a NULL check, causing a segmentation fault. This vulnerability is fixed in 9.2.0137.
A flaw was found in Vim. A NULL pointer dereference can occur when the NFA regex compiler processes a spec
Citrix
Citrix Security Bulletin CTX113814
vendor_citrix·CVSS 5.0
CVE-2007-0011 [MEDIUM] Citrix Security Bulletin CTX113814
Citrix Security Bulletin CTX113814
CVE References: CVE-2007-0011, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX112803
vendor_citrix·CVSS 5.0
CVE-2007-0011 [MEDIUM] Citrix Security Bulletin CTX112803
Citrix Security Bulletin CTX112803
CVE References: CVE-2007-0011, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-0011 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.4
CVE-2026-0011 [HIGH] CVE-2026-0011 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0011 :
NixOS vulnerability analysis and mitigation
In enableSystemPackageLPw of Settings.java, there is a possible way to prevent location access from working due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Source : NVD
## 8.4
Score
Published March 2, 2026
Severity HIGH
CNA Score 8.4
Affected Technologies
NixOS
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.2
Exploitation Probability (EPSS) N/A
Affected packages and libraries
android
Sources
NVD
Nix Severity HIGH No Fix Added at: Mar 04, 2026
## Get a CVE risk assessment
Get a prio
Bugzilla
CVE-2026-32249 vim: NFA regex engine NULL pointer dereference
bugzilla·2026-03-12·CVSS 5.5
CVE-2026-32249 [MEDIUM] CVE-2026-32249 vim: NFA regex engine NULL pointer dereference
CVE-2026-32249 vim: NFA regex engine NULL pointer dereference
Vim is an open source, command line text editor. From 9.1.0011 to before 9.2.0137, Vim's NFA regex compiler, when encountering a collection containing a combining character as the endpoint of a character range (e.g. [0-0\u05bb]), incorrectly emits the composing bytes of that character as separate NFA states. This corrupts the NFA postfix stack, resulting in NFA_START_COLL having a NULL out1 pointer. When nfa_max_width() subsequently traverses the compiled NFA to estimate match width for the look-behind assertion, it dereferences state->out1->out without a NULL check, causing a segmentation fault. This vulnerability is fixed in 9.2.0137.
2026-03-02
Published