CVE-2026-6891

Improper handling of symbolic links in the installer of My Image Garden for macOS Version 3.6.8 or earlier may allow a local attacker with login privileges to exploit a specially crafted symbolic link during installation to modify permissions of files for which they would not normally have authorization.
Configurations

No configuration.

History

21 Jul 2026, 12:10

Type Values Removed Values Added
Summary
  • (es) Manejo inadecuado de enlaces simbólicos en el instalador de My Image Garden para macOS Versión 3.6.8 o anterior podría permitir a un atacante local con privilegios de inicio de sesión explotar un enlace simbólico especialmente diseñado durante la instalación para modificar permisos de archivos para los cuales normalmente no tendrían autorización.

29 May 2026, 00:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-29 00:16

Updated : 2026-07-21 12:10


NVD link : CVE-2026-6891

Mitre link : CVE-2026-6891

CVE.ORG link : CVE-2026-6891


JSON object : View

Products Affected

No product.

CWE
CWE-59

Improper Link Resolution Before File Access ('Link Following')