Local Privilege Escalation in MidnightBSD Package Manager
CVE-2026-54576

5.8MEDIUM

Key Information:

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-54576?

The MidnightBSD Package Manager is susceptible to a local privilege escalation vulnerability due to improper handling of path-based operations during the installation of package files. Specifically, prior to version 2.7.8, the do_actual_install() function in libmport allowed a local attacker with write access to a target directory to create symbolic links that could manipulate file permissions and ownership. This could lead to significant security issues, as the attacker could redirect privileged changes to an arbitrary path, ultimately compromising the integrity of the filesystem. This vulnerability has been addressed in version 2.7.8, and users are urged to update to protect their systems.

Affected Version(s)

mport < 2.7.8

References

CVSS V4

Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.