Network Vulnerability in MidnightBSD Package Manager
CVE-2026-54586

6MEDIUM

Key Information:

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-54586?

The MidnightBSD Package Manager prior to version 2.7.8 contains a vulnerability in its index fetching methods that allows the usage of non-HTTPS repository and package mirror URLs. This lack of enforcement allows a network-positioned attacker to intercept and manipulate package indexes and downloads, potentially leading to compromised package selection and integrity. The issue was resolved in the 2.7.8 update, which mandates secure URL usage.

Affected Version(s)

mport < 2.7.8

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.