HIGHCVSS 7.8Vulnerability

CVE-2026-7867

A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization checking on the 'as-user' option in the org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method. This allows the attacker to spoof the 'as-user' parameter, mounting filesystems on behalf of arbitrary users, including privileged accounts. This can lead to local privilege escalation through mount point injection and manipulation of the mount namespace visible to privileged users.

Properties

severity
HIGH
cvss_score
7.8
cvss_severity
HIGH
epss_score
0.00168
retrieved_at
2026-10-09T15:44:39+00:00
last_source
FIRST EPSS
score
7.8
cve_id
CVE-2026-7867
cvss_vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
signal_observed_at
2026-09-11T17:54:55+00:00
vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
published_at
2026-08-06T22:18:33.100
last_modified
2026-09-08T08:17:12.173
epss_percentile
0.05635

Related Entities (3)

ENRICHED_BY (1)

→[Source]FIRST EPSS

DESCRIBED_BY (1)

→[Source]NVD

HAS_WEAKNESS (1)

→[Weakness]Incorrect Authorization

Explore deeper with Ninja Signal's threat intelligence graph