LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-54369

Published
CVSS7.1
Severityhigh
WeaknessCWE-59
ExploitedNot in CISA KEV

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Description

acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-54369

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-54369.