CVE-2026-46388

osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. Prior to 5.23.1, an unprivileged attacker can read the contents of an osquery file carve until the carve completes and the temporary files are deleted because in-progress carve directories are not created with private permissions. If the carve targets a directory that the attacker controls, arbitrary file reads are possible, such as sensitive local files. This issue is fixed in version 5.23.1.
Configurations

No configuration.

History

10 Jul 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-10 16:16

Updated : 2026-07-10 20:16


NVD link : CVE-2026-46388

Mitre link : CVE-2026-46388

CVE.ORG link : CVE-2026-46388


JSON object : View

Products Affected

No product.

CWE
CWE-279

Incorrect Execution-Assigned Permissions

CWE-378

Creation of Temporary File With Insecure Permissions

CWE-379

Creation of Temporary File in Directory with Insecure Permissions