CVE-2018-16497

Executive Summary

CVE-2018-16497 exposes a privilege‑escalation flaw in Versa Analytics. Cron jobs scheduled as root execute a writable script owned by users in the versa group. An attacker who can add or modify such a script can gain root privileges on the host, compromising the entire system. The vulnerability is not yet listed in CISA KEV.


Authoritative CVE Metadata - CVSS Base Score: 7.8 (HIGH) - Published: 2021-05-26T19:15:08.643 - Last Modified: 2026-08-31T17:54:28.843

Original Description: In Versa Analytics, the cron jobs are used for scheduling tasks by executing commands at specific dates and times on the server. If the job is run as the user root, there is a potential privilege escalation vulnerability. In this case, the job runs a script as root that is writable by users who are members of the versa group.

"Know, first, who you are, and then adorn yourself accordingly."

— Epictetus
Source: NVD