Privilege Escalation Vulnerability in GNU libextractor by GNU
CVE-2026-100310

7.3HIGH

Key Information:

Vendor

Gnu

Vendor
CVE Published:
25 September 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-100310?

GNU libextractor prior to version 1.16 is susceptible to a privilege escalation vulnerability due to the improper handling of the LIBEXTRACTOR_PREFIX environment variable. This flaw allows a local attacker to exploit the system by loading plugins from an untrusted search path, potentially executing arbitrary code with elevated privileges. Attackers can place a malicious plugin in a directory specified by LIBEXTRACTOR_PREFIX, which is then executed by setuid or setgid programs, leading to critical security risks.

Affected Version(s)

libextractor 0 < 1.16

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Haitam Lazaar
.