CVE-2026-72694

EUVD-2026-55977
A flaw was found in MRTG. When the MRTG daemon is started as a root user and subsequently drops privileges, a local, low-privileged attacker can exploit a symbolic link (symlink) following vulnerability. By influencing or pre-placing a symlink in the process ID (PID) file path, the attacker can trick the root process into changing the ownership of an arbitrary existing file to the daemon user. This can lead to local privilege escalation, allowing unauthorized access to or modification of sensitive files.
Link Following
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.1 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 5.41%
Debian logo
Debian Releases
Debian Product
Codename
mrtg
bookworm
postponed
forky
2.17.10-16
fixed
sid
2.17.10-16
fixed
trixie
2.17.10-13+deb13u2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
mrtg
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
xenial
needs-triage
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
mrtg
RHEL 9
0:2.17.7-12.el9_8.1
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
mrtg
Amazon Linux 2
0:2.17.4-11.amzn2.0.3
fixed
mrtg-debuginfo
Amazon Linux 2
0:2.17.4-11.amzn2.0.3
fixed