-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Advisory ID: SYSS-2026-029 Product: AudioCodes One Voice Operations Center (OVOC) Manufacturer: AudioCodes Ltd. Affected Version(s): <= 8.4.3615, future releases may also be affected (not yet fixed) Tested Version(s): 8.4.3079 on Rocky Linux 8.10 Vulnerability Type: Improper Privilege Management (CWE-269) Risk Level: Medium Solution Status: Open Manufacturer Notification: 2026-04-22 Solution Date: Not yet fixed Public Disclosure: 2026-07-09 CVE Reference: Not yet assigned Author of Advisory: Moritz Abrell, SySS GmbH ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Overview: AudioCodes One Voice Operations Center (OVOC) is a web-based management and monitoring solution for Session Border Controllers. The manufacturer describes OVOC as "a voice network management solution" and states that it combines device management with quality monitoring (see [1]). OVOC is affected by a local privilege escalation vulnerability. The directory "/opt/ACEMS" is owned by the low-privileged service user "emsadmin", while root's crontab executes scripts from a subdirectory below this path. An attacker with code execution as "emsadmin" can rename the root-owned server directory and replace it with an attacker-controlled directory containing a malicious script with the same name as a cron-executed script. When the root cron job runs, the attacker-controlled script is executed with root privileges. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Vulnerability Details: The relevant directory permissions are: drwxr-xr-x emsadmin dba /opt/ACEMS drwxr-xr-x root root /opt/ACEMS/server_8.4.3079 -rwxr-xr-x root root /opt/ACEMS/server_8.4.3079/runOvocStatistics -rwxr-xr-x root root /opt/ACEMS/server_8.4.3079/runUriStatistics The root crontab contains the following entries: 15 * * * * /opt/ACEMS/server_8.4.3079/runOvocStatistics >> /var/log/ems/summary_stat.log 2>&1 15 * * * * /opt/ACEMS/server_8.4.3079/runUriStatistics >> /var/log/ems/summary_uri_stat.log 2>&1 10 * * * * /opt/ACEMS/server_8.4.3079/runTeamsStatistics >> /var/log/ems/summary_teams_stat.log 2>&1 30 * * * * /opt/ACEMS/server_8.4.3079/runPmFilesJob_unix >> /var/log/ems/pmLog.csv 2>&1 Although "/opt/ACEMS/server_8.4.3079" and the cron-executed scripts are owned by root, Unix rename permissions are controlled by the parent directory. Because "/opt/ACEMS" is owned by "emsadmin", the "emsadmin" user can rename child entries of this directory. This includes the root-owned "server_8.4.3079" directory. As a result, an attacker with an "emsadmin" shell can 1. rename "/opt/ACEMS/server_8.4.3079" to a backup path, 2. create a new "/opt/ACEMS/server_8.4.3079" directory, 3. place an attacker-controlled "runOvocStatistics" script inside it, or 4. wait until root's cron job executes the script. The attack does not require write permission to the original "runOvocStatistics" file. The ability to rename the parent directory entry is sufficient. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Proof of Concept (PoC): The following PoC demonstrates the issue from an "emsadmin" context: 1. Rename the real server directory and create a replacement directory: mv /opt/ACEMS/server_8.4.3079 /opt/ACEMS/server_8.4.3079.backup mkdir -p /opt/ACEMS/server_8.4.3079 2. Create a temporary proof script at the cron-executed path: /opt/ACEMS/server_8.4.3079/runOvocStatistics 3. Make the script executable: chmod 755 /opt/ACEMS/server_8.4.3079/runOvocStatistics 3. Wait for the root cron job at minute 15 of the hour. Successful exploitation gives the attacker full root control of the OVOC host operating system. In combination with SYSS-2026-028 (see [3]), this can be chained to an authenticated RCE with privilege escalation to root. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Solution: Not yet fixed ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Disclosure Timeline: 2026-04-17: Vulnerability discovered 2026-04-22: Vulnerability reported to the manufacturer 2026-04-30: Report assigned to the correct department of the manufacturer 2026-05-11: According to the manufacturer, a fix for the vulnerability is planned for the release expected by the end of May 2026-06-29: Request for an update 2026-06-29: Manufacturer response: vulnerability will not be fixed 2026-07-09: Public disclosure ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ References: [1] AudioCodes One Voice Operations Center product page https://www.audiocodes.com/solutions-products/products/management-products-solutions/one-voice-operations-center [2] SySS Security Advisory SYSS-2026-029 https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2026-029.txt [3] SySS Security Advisory SYSS-2026-028 https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2026-028.txt [4] SySS Responsible Disclosure Policy https://www.syss.de/en/responsible-disclosure-policy ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Credits: This security vulnerability was found by Moritz Abrell of SySS GmbH. E-Mail: moritz.abrell@syss.de Public Key: https://www.syss.de/fileadmin/dokumente/PGPKeys/Moritz_Abrell.asc Key Fingerprint: 2927 7EB6 1A20 0679 79E9 87E6 AE0C 9BF8 F134 8B53 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Disclaimer: The information provided in this security advisory is provided "as is" and without warranty of any kind. Details of this security advisory may be updated in order to provide as accurate information as possible. The latest version of this security advisory should be published by the author. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Copyright: Creative Commons - Attribution (by) - Version 4.0 URL: https://creativecommons.org/licenses/by/4.0/deed.en -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEKSd+thogBnl56Yfmrgyb+PE0i1MFAmpN7UAACgkQrgyb+PE0 i1MLmRAArjE07g6VbeYJP+ozu8espojUOZWDbt5uvpTwHmt0s//a+0PDUiMshMXt cE952EOEE4eeCHHaGMo59A/4Q0Vn9GnQRaewgbDSbrVUACP3dfsbvKzK/+tqkNEU CLp/SGtfjDUzgN5s9i9rDIh/hX9/fbqPMK4XaaeKspyWl14vE2U4sUho3Xl8QtSw o9FQwHJ3vwnAsY4OyRNpz71WUvKmDseroa6DSlDDrROsGFcprnjALw8yuiRG3Qxf /w60A3FrYapzRe6Owh+HbJ4iMBjJbPPQt3qOZihxPSps2YsnY5upCqNDMc2zFG2W slp6Uqjc09xsp039tPOmP7deAr5bmfzxm85UVIIuIgZPDeonk+VvvnYOtZcBPE4l A2nrfAEmWeQXBEA4tSiSpdhhxJImwbueWLEZPqH3WYwrFSJVMJgYMpwKEz9xAaoZ +1lLW5cGdBqxHkZeTr0FrKadyAsS+O7zgGeWaDQBdMq5QL7G7j+O/OgdQwHPCnlu HGFN/8SxU0yZTTMlhPXQ0N3pYaZIJL229pQ5lNLt3HVgXlaCP3YVHrPly9H1lUUO iWgYviprX9UJXw4IVOg5IwW4lU6v2sPNPJYAN0CfJctnMqXLxfuPwHs76xcC7NSn M27ReXMmjKsG103MYk8tbSpzhw5/KY8YMYxfZd87KukxfQ/i6Ig= =vU5T -----END PGP SIGNATURE-----