Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 9

Количество 9

ubuntu логотип

CVE-2026-72694

18 дней назад

A flaw was found in MRTG. When the MRTG daemon is started as a root user and subsequently drops privileges, a local, low-privileged attacker can exploit a symbolic link (symlink) following vulnerability. By influencing or pre-placing a symlink in the process ID (PID) file path, the attacker can trick the root process into changing the ownership of an arbitrary existing file to the daemon user. This can lead to local privilege escalation, allowing unauthorized access to or modification of sensitive files.

CVSS3: 7.1
EPSS: Низкий
redhat логотип

CVE-2026-72694

18 дней назад

A flaw was found in MRTG. When the MRTG daemon is started as a root user and subsequently drops privileges, a local, low-privileged attacker can exploit a symbolic link (symlink) following vulnerability. By influencing or pre-placing a symlink in the process ID (PID) file path, the attacker can trick the root process into changing the ownership of an arbitrary existing file to the daemon user. This can lead to local privilege escalation, allowing unauthorized access to or modification of sensitive files.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-72694

18 дней назад

A flaw was found in MRTG. When the MRTG daemon is started as a root user and subsequently drops privileges, a local, low-privileged attacker can exploit a symbolic link (symlink) following vulnerability. By influencing or pre-placing a symlink in the process ID (PID) file path, the attacker can trick the root process into changing the ownership of an arbitrary existing file to the daemon user. This can lead to local privilege escalation, allowing unauthorized access to or modification of sensitive files.

CVSS3: 7.1
EPSS: Низкий
debian логотип

CVE-2026-72694

18 дней назад

A flaw was found in MRTG. When the MRTG daemon is started as a root us ...

CVSS3: 7.1
EPSS: Низкий
rocky логотип

RLSA-2026:57600

8 дней назад

Important: mrtg security update

EPSS: Низкий
rocky логотип

RLSA-2026:57596

8 дней назад

Important: mrtg security update

EPSS: Низкий
github логотип

GHSA-pqrp-p4c6-2q4g

18 дней назад

A flaw was found in MRTG. When the MRTG daemon is started as a root user and subsequently drops privileges, a local, low-privileged attacker can exploit a symbolic link (symlink) following vulnerability. By influencing or pre-placing a symlink in the process ID (PID) file path, the attacker can trick the root process into changing the ownership of an arbitrary existing file to the daemon user. This can lead to local privilege escalation, allowing unauthorized access to or modification of sensitive files.

CVSS3: 7.1
EPSS: Низкий
oracle-oval логотип

ELSA-2026-57600

9 дней назад

ELSA-2026-57600: mrtg security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-57596

9 дней назад

ELSA-2026-57596: mrtg security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-72694

A flaw was found in MRTG. When the MRTG daemon is started as a root user and subsequently drops privileges, a local, low-privileged attacker can exploit a symbolic link (symlink) following vulnerability. By influencing or pre-placing a symlink in the process ID (PID) file path, the attacker can trick the root process into changing the ownership of an arbitrary existing file to the daemon user. This can lead to local privilege escalation, allowing unauthorized access to or modification of sensitive files.

CVSS3: 7.1
0%
Низкий
18 дней назад
redhat логотип
CVE-2026-72694

A flaw was found in MRTG. When the MRTG daemon is started as a root user and subsequently drops privileges, a local, low-privileged attacker can exploit a symbolic link (symlink) following vulnerability. By influencing or pre-placing a symlink in the process ID (PID) file path, the attacker can trick the root process into changing the ownership of an arbitrary existing file to the daemon user. This can lead to local privilege escalation, allowing unauthorized access to or modification of sensitive files.

CVSS3: 7.1
0%
Низкий
18 дней назад
nvd логотип
CVE-2026-72694

A flaw was found in MRTG. When the MRTG daemon is started as a root user and subsequently drops privileges, a local, low-privileged attacker can exploit a symbolic link (symlink) following vulnerability. By influencing or pre-placing a symlink in the process ID (PID) file path, the attacker can trick the root process into changing the ownership of an arbitrary existing file to the daemon user. This can lead to local privilege escalation, allowing unauthorized access to or modification of sensitive files.

CVSS3: 7.1
0%
Низкий
18 дней назад
debian логотип
CVE-2026-72694

A flaw was found in MRTG. When the MRTG daemon is started as a root us ...

CVSS3: 7.1
0%
Низкий
18 дней назад
rocky логотип
RLSA-2026:57600

Important: mrtg security update

0%
Низкий
8 дней назад
rocky логотип
RLSA-2026:57596

Important: mrtg security update

0%
Низкий
8 дней назад
github логотип
GHSA-pqrp-p4c6-2q4g

A flaw was found in MRTG. When the MRTG daemon is started as a root user and subsequently drops privileges, a local, low-privileged attacker can exploit a symbolic link (symlink) following vulnerability. By influencing or pre-placing a symlink in the process ID (PID) file path, the attacker can trick the root process into changing the ownership of an arbitrary existing file to the daemon user. This can lead to local privilege escalation, allowing unauthorized access to or modification of sensitive files.

CVSS3: 7.1
0%
Низкий
18 дней назад
oracle-oval логотип
ELSA-2026-57600

ELSA-2026-57600: mrtg security update (IMPORTANT)

0%
Низкий
9 дней назад
oracle-oval логотип
ELSA-2026-57596

ELSA-2026-57596: mrtg security update (IMPORTANT)

0%
Низкий
9 дней назад

Уязвимостей на страницу

exploitDog - Комплексное решение для обнаружения, оценки и устранения уязвимостей.