CVEFinder.io

CVE-2026-54230

⚠️ high
🔍 Scan for this CVE
Summary

A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write output files using shell redirections without the O_NOFOLLOW flag. If the target file is replaced with a symlink, the shell process running as root follows the symlink and writes content to the symlink target, allowing arbitrary file overwrites on the system.

CVSS Score
7.0
High
EPSS Score
0.2
Exploit Probability
Published Date
2026-06-13
First Seen: 2026-06-14
📊 Relative Risk Intelligence

This CVE is Moderate Risk - more severe than 50.7% of all 350,976 vulnerabilities in our database.

#172,912
Above average severity
Severity Percentile
🎯 CISA SSVC Assessment Updated: Jun 15, 2026
🔍 Exploitation Status
None
No known exploits
⚙️ Automatable
NO
Requires human interaction
💥 Technical Impact
Total
Complete system compromise possible
🏆 Discovered By
Red Hat would like to thank Red Team (Deutsche Telekom Security GmbH) for reporting this issue.
SSVC data provided by CISA
Last Modified 2026-08-26
Source NVD 🔗
CVSS Vector 3.1 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE IDs (Weakness Types)

📦 Affected Products 6

🔗 References 4

🔗 Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2026-11861 ⛔ critical 9.6 0.2 A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Direct... 2026-08-20
CVE-2026-13097 ⚠️ high 8.7 0.3 A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attribut... 2026-08-20
CVE-2026-73196 🔶 medium 4.3 0.2 A flaw was found in FreeIPA. A low-privilege authenticated user can exploit this vulnerability by submitting an oversize... 2026-08-20
CVE-2026-73197 ⚠️ high 7.5 0.3 A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by sending oversized form... 2026-08-20
CVE-2026-73198 ⚠️ high 7.5 0.3 A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in the `/ipa/i18n_messages` ... 2026-08-20
CVE-2026-19617 🔶 medium 5.5 0.1 A flaw was found in libdm. A local attacker could craft a malicious Logical Volume Manager (LVM) metadata configuration ... 2026-08-14
These CVEs affect the same products