HIGHVulnerability

CVE-2026-54369

acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation.

Properties

severity
HIGH
score
7.1
cve_id
CVE-2026-54369
vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
published_at
2026-06-29T14:16:57.487
last_modified
2026-08-11T13:18:59.133

Related Entities (2)

HAS_WEAKNESS (1)

[Weakness]Improper Link Resolution Before File Access ('Link Following')

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-54369 — Ninja Signal Threat Intelligence | Ninja Signal