Symlink Following Vulnerability in openCryptoki PKCS#11 Library for Linux and AIX
CVE-2026-23893

6.8MEDIUM

Key Information:

Vendor
CVE Published:
22 January 2026

What is CVE-2026-23893?

The openCryptoki PKCS#11 library for Linux and AIX is vulnerable to a symlink-following issue affecting versions 2.3.2 and later. This vulnerability allows a token-group user to manipulate file operations in privileged contexts by placing symlinks within group-writable token directories. Consequently, attackers could redirect these operations to unauthorized filesystem targets, leading to potential privilege escalation or data exposure, especially when administrative tools are run with elevated privileges, resetting ownership or permissions on files. While this issue has been addressed in commit 5e6e4b4, the fix is not yet available in a release.

Affected Version(s)

opencryptoki >= 2.3.2

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.