Symlink Following Vulnerability in openCryptoki PKCS#11 Library for Linux and AIX
CVE-2026-23893
6.8MEDIUM
What is CVE-2026-23893?
The openCryptoki PKCS#11 library for Linux and AIX is vulnerable to a symlink-following issue affecting versions 2.3.2 and later. This vulnerability allows a token-group user to manipulate file operations in privileged contexts by placing symlinks within group-writable token directories. Consequently, attackers could redirect these operations to unauthorized filesystem targets, leading to potential privilege escalation or data exposure, especially when administrative tools are run with elevated privileges, resetting ownership or permissions on files. While this issue has been addressed in commit 5e6e4b4, the fix is not yet available in a release.
Affected Version(s)
opencryptoki >= 2.3.2
