Local Privilege Escalation in MidnightBSD Package Manager
CVE-2026-54576
5.8MEDIUM
What is CVE-2026-54576?
The MidnightBSD Package Manager is susceptible to a local privilege escalation vulnerability due to improper handling of path-based operations during the installation of package files. Specifically, prior to version 2.7.8, the do_actual_install() function in libmport allowed a local attacker with write access to a target directory to create symbolic links that could manipulate file permissions and ownership. This could lead to significant security issues, as the attacker could redirect privileged changes to an arbitrary path, ultimately compromising the integrity of the filesystem. This vulnerability has been addressed in version 2.7.8, and users are urged to update to protect their systems.
Affected Version(s)
mport < 2.7.8
