CVE-2026-54424
Raw vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVSS and EPSS are reproduced from their sources (NVD, FIRST EPSS). Risk Priority is our own derived reading, not an NVD score.
Summary
CVE-2026-54424 is a high-severity Incorrect Use of Privileged APIs (CWE-648) vulnerability. Its CVSS base score is 8.4 (High).
Operationally, exploitation aligns with the MITRE ATT&CK technique Abuse Elevation Control Mechanism (T1548); ranked at the 8th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified map to SA-11 (Developer Testing and Evaluation) and AC-3 (Access Enforcement) — see the control section below for these in your framework.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2026-41655
Vulnerability Data
An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Privilege. This issue affects Parsec through v2026-05-04.0. The patched version is Parsec for Windows version 150-104a. A user can generate a…
more
situation where there is an instance of parsecd.exe running as NT AUTHORITY\SYSTEM with a user-controlled value of the AppData environment variable.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise Techniques
CVEs Like This One
Affected Assets
Mitigating Controls
Control response
—
—
—
V3.5.2V6.4.6
Mitigating Controls (NIST 800-53 r5) AI
Developer testing and evaluation can discover incorrect calls to privileged APIs before deployment.
Enforces authorization checks around privileged operations so that an API requiring elevated rights cannot be reached or misused without proper rights.
Least-privilege assignment directly reduces both the availability of privileged APIs and the blast radius when they are invoked incorrectly.
Security engineering principles include correct use of privileged interfaces and safe invocation patterns that stop the weakness from being introduced.
Mitigating Controls (NIST CSF 2.0) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.
Secure SDLC practices directly enforce correct usage of privileged APIs during development.
Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI
Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.
Restricting privileged utility programs limits the exposure of privileged APIs to misuse.
Privileged access rights directly govern the correct use of privileged APIs and reduce misuse.
Secure development lifecycle includes API usage standards that can prevent incorrect privileged calls.
Application security requirements can specify correct invocation of privileged APIs.
Secure architecture principles guide proper privilege separation and API usage.
Secure coding standards can enforce correct usage of privileged APIs.