CVE-2026-54369
acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation.
CVSS
- Version: 4.0
- Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Base score: 8.4
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.15%
- Percentile among all scored CVEs: 4
- Score date: 10/5/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
🎯 ATT&CK techniques
How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.
- Exploitation
T1068Exploitation for Privilege Escalationprivilege escalation85 %
Vector AV:L/PR:L sin UI, CWE-59 symlink traversal. Acceso local con privilegios permiten escalar a root manipulando ACLs mediante enlaces simbólicos en rutas procesadas por libacl.
Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.
🛡️ ATT&CK mitigations that cover these techniques
Affected technologies (1)
⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.
CWEs
- CWE-59
- CWE-59
References
- https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=24a227d0ab8576612194f8a56c2314389adc74a5
- https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=3589787cd589b34bdd9265936e17190b6d3f17d1
- https://www.vulncheck.com/advisories/acl-symlink-traversal-privilege-escalation-via-libacl-functions
- https://access.redhat.com/errata/RHSA-2026:34351
- https://access.redhat.com/errata/RHSA-2026:42736
- https://access.redhat.com/errata/RHSA-2026:42739
- https://access.redhat.com/errata/RHSA-2026:43420
- https://access.redhat.com/errata/RHSA-2026:44481
- https://access.redhat.com/errata/RHSA-2026:46836
- https://access.redhat.com/errata/RHSA-2026:50205
- https://access.redhat.com/errata/RHSA-2026:53371
- https://access.redhat.com/errata/RHSA-2026:54769
- https://access.redhat.com/errata/RHSA-2026:58981
- https://access.redhat.com/errata/RHSA-2026:64805
- https://access.redhat.com/errata/RHSA-2026:67140
- https://access.redhat.com/errata/RHSA-2026:67142
- https://access.redhat.com/errata/RHSA-2026:67144
- https://access.redhat.com/security/cve/CVE-2026-54369
- https://bugzilla.redhat.com/show_bug.cgi?id=2490277
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54369.json
Raw JSON (NVD)
Show
{
"id": "CVE-2026-54369",
"cveTags": [
{
"tags": [
"unsupported-when-assigned"
],
"sourceIdentifier": "disclosure@vulncheck.com"
}
],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-54369",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-06-29T13:56:13.338794Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "disclosure@vulncheck.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.1,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.2,
"exploitabilityScore": 1.8
},
{
"type": "Secondary",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.1,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.2,
"exploitabilityScore": 1.8
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "disclosure@vulncheck.com",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 8.4,
"Automatable": "NOT_DEFINED",
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"privilegesRequired": "LOW",
"subIntegrityImpact": "NONE",
"vulnIntegrityImpact": "HIGH",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"vulnAvailabilityImpact": "NONE",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "disclosure@vulncheck.com",
"affectedData": [
{
"repo": "https://savannah.nongnu.org/projects/acl/",
"vendor": "acl project",
"product": "acl",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "2.4.0",
"versionType": "semver"
}
],
"defaultStatus": "affected"
}
]
},
{
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
"affectedData": [
{
"cpes": [
"cpe:/o:redhat:enterprise_linux:10.2"
],
"vendor": "Red Hat",
"product": "Red Hat Enterprise Linux 10",
"versions": [
{
"status": "unaffected",
"version": "0:2.4.0-1.el10_2",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "acl",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/o:redhat:enterprise_linux_eus:10.0"
],
"vendor": "Red Hat",
"product": "Red Hat Enterprise Linux 10.0 Extended Update Support",
"versions": [
{
"status": "unaffected",
"version": "0:2.4.0-0.el10_0.1",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "acl",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/o:redhat:enterprise_linux:8"
],
"vendor": "Red Hat",
"product": "Red Hat Enterprise Linux 8",
"versions": [
{
"status": "unaffected",
"version": "0:2.4.0-1.el8_10",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "acl",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:enterprise_linux:9",
"cpe:/o:redhat:enterprise_linux:9"
],
"vendor": "Red Hat",
"product": "Red Hat Enterprise Linux 9",
"versions": [
{
"status": "unaffected",
"version": "0:2.4.0-1.el9_8",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "acl",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift:4.22::el9"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift Container Platform 4.22",
"versions": [
{
"status": "unaffected",
"version": "4.22.9.8.202608130832-0",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "rhcos",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:discovery:2::el9"
],
"vendor": "Red Hat",
"product": "Red Hat Discovery 2",
"versions": [
{
"status": "unaffected",
"version": "1784821670",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "discovery/discovery-server-rhel9",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:discovery:2::el9"
],
"vendor": "Red Hat",
"product": "Red Hat Discovery 2",
"versions": [
{
"status": "unaffected",
"version": "1784821750",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "discovery/discovery-ui-rhel9",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:hummingbird:1"
],
"vendor": "Red Hat",
"product": "Red Hat Hardened Images",
"versions": [
{
"status": "unaffected",
"version": "2.4.0-0.1.hum1",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "acl-main",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:insights_proxy:1.5::el9"
],
"vendor": "Red Hat",
"product": "Red Hat Insights proxy 1.5",
"versions": [
{
"status": "unaffected",
"version": "1786433656",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "insights-proxy/insights-proxy-container-rhel9",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift_distributed_tracing:3.10::el9"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift distributed tracing 3.10.2",
"versions": [
{
"status": "unaffected",
"version": "1785704636",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "rhosdt/opentelemetry-collector-rhel9",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:rhui:5::el9"
],
"vendor": "Red Hat",
"product": "Red Hat Update Infrastructure 5",
"versions": [
{
"status": "unaffected",
"version": "1784794818",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "rhui5/cds-kubernetes-rhel9",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:rhui:5::el9"
],
"vendor": "Red Hat",
"product": "Red Hat Update Infrastructure 5",
"versions": [
{
"status": "unaffected",
"version": "1784794778",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "rhui5/cds-rhel9",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:rhui:5::el9"
],
"vendor": "Red Hat",
"product": "Red Hat Update Infrastructure 5",
"versions": [
{
"status": "unaffected",
"version": "1784795112",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "rhui5/haproxy-rhel9",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:rhui:5::el9"
],
"vendor": "Red Hat",
"product": "Red Hat Update Infrastructure 5",
"versions": [
{
"status": "unaffected",
"version": "1784794289",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "rhui5/installer-rhel9",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:rhui:5::el9"
],
"vendor": "Red Hat",
"product": "Red Hat Update Infrastructure 5",
"versions": [
{
"status": "unaffected",
"version": "1784795076",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "rhui5/rhua-rhel9",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:rhui:5::el9"
],
"vendor": "Red Hat",
"product": "Red Hat Update Infrastructure 5",
"versions": [
{
"status": "unaffected",
"version": "1787241211",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "rhui5/cds-kubernetes-tp-rhel9",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:rhui:5::el9"
],
"vendor": "Red Hat",
"product": "Red Hat Update Infrastructure 5",
"versions": [
{
"status": "unaffected",
"version": "1787135742",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "rhui5/installer-tp-rhel9",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:rhui:5::el9"
],
"vendor": "Red Hat",
"product": "Red Hat Update Infrastructure 5",
"versions": [
{
"status": "unaffected",
"version": "1787241260",
"lessThan": "*",
"versionType": "rpm"
}
],
"packageName": "rhui5/rhua-tp-rhel9",
"collectionURL": "https://catalog.redhat.com/software/containers/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/o:redhat:enterprise_linux:6"
],
"vendor": "Red Hat",
"product": "Red Hat Enterprise Linux 6",
"packageName": "acl",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/o:redhat:enterprise_linux:7"
],
"vendor": "Red Hat",
"product": "Red Hat Enterprise Linux 7",
"packageName": "acl",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
},
{
"cpes": [
"cpe:/a:redhat:openshift:4"
],
"vendor": "Red Hat",
"product": "Red Hat OpenShift Container Platform 4",
"packageName": "openshift/ose-rhel-coreos-9",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "affected"
}
]
}
],
"published": "2026-06-29T14:16:57.487",
"references": [
{
"url": "https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=24a227d0ab8576612194f8a56c2314389adc74a5",
"source": "disclosure@vulncheck.com"
},
{
"url": "https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=3589787cd589b34bdd9265936e17190b6d3f17d1",
"source": "disclosure@vulncheck.com"
},
{
"url": "https://www.vulncheck.com/advisories/acl-symlink-traversal-privilege-escalation-via-libacl-functions",
"source": "disclosure@vulncheck.com"
},
{
"url": "https://access.redhat.com/errata/RHSA-2026:34351",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
},
{
"url": "https://access.redhat.com/errata/RHSA-2026:42736",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
},
{
"url": "https://access.redhat.com/errata/RHSA-2026:42739",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
},
{
"url": "https://access.redhat.com/errata/RHSA-2026:43420",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
},
{
"url": "https://access.redhat.com/errata/RHSA-2026:44481",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
},
{
"url": "https://access.redhat.com/errata/RHSA-2026:46836",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
},
{
"url": "https://access.redhat.com/errata/RHSA-2026:50205",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
},
{
"url": "https://access.redhat.com/errata/RHSA-2026:53371",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
},
{
"url": "https://access.redhat.com/errata/RHSA-2026:54769",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
},
{
"url": "https://access.redhat.com/errata/RHSA-2026:58981",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
},
{
"url": "https://access.redhat.com/errata/RHSA-2026:64805",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
},
{
"url": "https://access.redhat.com/errata/RHSA-2026:67140",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
},
{
"url": "https://access.redhat.com/errata/RHSA-2026:67142",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
},
{
"url": "https://access.redhat.com/errata/RHSA-2026:67144",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
},
{
"url": "https://access.redhat.com/security/cve/CVE-2026-54369",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2490277",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
},
{
"url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54369.json",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "disclosure@vulncheck.com",
"description": [
{
"lang": "en",
"value": "CWE-59"
}
]
},
{
"type": "Secondary",
"source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
"description": [
{
"lang": "en",
"value": "CWE-59"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation."
}
],
"lastModified": "2026-09-14T13:18:40.197",
"sourceIdentifier": "disclosure@vulncheck.com"
}