Local User Injection Vulnerability in Collectl by Red Hat
CVE-2026-103431

7.7HIGH

Key Information:

Status
Vendor
CVE Published:
1 October 2026

What is CVE-2026-103431?

The vulnerability found in Collectl prior to version 4.3.20.2 allows unprivileged local users to exploit improperly sanitized ANSI/VT100 terminal escape sequences received from remote instances. This enables them to inject harmful escape sequences into the terminal session of an operator running Collectl, potentially leading to unauthorized command execution or misleading terminal outputs. This issue underscores the importance of input sanitization in monitoring tools to prevent local privilege escalation and maintain system integrity.

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was discovered by Laurence Oberman (Red Hat) and Nathan Scott (Red Hat).
.