Local Directory Traversal Vulnerability in MidnightBSD Package Manager
CVE-2026-54587

5.8MEDIUM

Key Information:

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-54587?

A vulnerability in the MidnightBSD Package Manager allows a local attacker to exploit directory handling mechanisms prior to version 2.7.8. By using techniques such as dot-dot traversal or substitution of symbolic links, an attacker with access to modify parts of the target installation tree can manipulate directory creation and change attributes beyond the designated package directories. This could lead to unauthorized access or manipulation of the system's file structure. The issue has been resolved in version 2.7.8, enhancing the security of the package manager.

Affected Version(s)

mport < 2.7.8

References

CVSS V4

Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.