Package management vulnerability in MidnightBSD
CVE-2026-54577

2LOW

Key Information:

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-54577?

In versions prior to 2.7.8 of the MidnightBSD Package Manager, a flaw existed in the audit command implementation. When specifying options like '-r' before a package, the original arguments passed led to an unintentional auditing of the option instead of the targeted package. This misconfiguration resulted in the inability to properly identify vulnerable packages, creating a risk for users relying on the tool for package management. With the update in version 2.7.8, the parsing process has been corrected, ensuring that the command properly resets the option index before using the adjusted arguments, thus enhancing the reliability of the auditing process.

Affected Version(s)

mport < 2.7.8

References

CVSS V4

Score:
2
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.