CVE-2026-54369

acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation.
Configurations

No configuration.

History

02 Jul 2026, 12:17

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:34351 -

30 Jun 2026, 03:21

Type Values Removed Values Added
References
  • () https://access.redhat.com/security/cve/CVE-2026-54369 -
  • () https://bugzilla.redhat.com/show_bug.cgi?id=2490277 -
  • () https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54369.json -

29 Jun 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-29 14:16

Updated : 2026-07-15 01:16


NVD link : CVE-2026-54369

Mitre link : CVE-2026-54369

CVE.ORG link : CVE-2026-54369


JSON object : View

Products Affected

No product.

CWE
CWE-59

Improper Link Resolution Before File Access ('Link Following')