HIGHVulnerability

CVE-2026-54230

A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write output files using shell redirections without the O_NOFOLLOW flag. If the target file is replaced with a symlink, the shell process running as root follows the symlink and writes content to the symlink target, allowing arbitrary file overwrites on the system.

Properties

severity
HIGH
score
7
cve_id
CVE-2026-54230
vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
published_at
2026-06-13T03:16:21.733
last_modified
2026-08-12T16:17:06.573

Related Entities (7)

HAS_WEAKNESS (1)

[Weakness]Improper Link Resolution Before File Access ('Link Following')

DESCRIBED_BY (1)

[Source]NVD

AFFECTS_PRODUCT (5)

[Product]
[Product]
[Product]
[Product]
[Product]

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-54230 — Ninja Signal Threat Intelligence | Ninja Signal