A vulnerability described as critical has been identified in nodejs Node.js up to 22.23.1/24.18.0/26.5.0. Impacted is an unknown function of the component Permission Model. Such manipulation leads to improper privilege management.

This vulnerability is referenced as CVE-2026-58043. It is possible to launch the attack remotely. No exploit is available.