CVE-2026-7867

EUVD-2026-54277
A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization checking on the 'as-user' option in the org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method. This allows the attacker to spoof the 'as-user' parameter, mounting filesystems on behalf of arbitrary users, including privileged accounts. This can lead to local privilege escalation through mount point injection and manipulation of the mount namespace visible to privileged users.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 7.21%
Debian logo
Debian Releases
Debian Product
Codename
udisks2
bookworm
2.9.4-4+deb12u2
fixed
bookworm (security)
2.9.4-4+deb12u2
fixed
bullseye
2.9.2-2+deb11u1
fixed
bullseye (security)
2.9.2-2+deb11u3
fixed
forky
vulnerable
sid
vulnerable
trixie
vulnerable
trixie (security)
2.10.1-12.1+deb13u2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
udisks2
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
trusty
needs-triage
xenial
needs-triage