Command Injection Vulnerability in Linuxfabrik Monitoring Plugins and linuxfabrik-lib
CVE-2026-55426

7.8HIGH

Key Information:

Vendor
CVE Published:
18 August 2026

What is CVE-2026-55426?

A command injection vulnerability exists in Linuxfabrik Monitoring Plugins and linuxfabrik-lib, allowing unauthenticated attackers to execute arbitrary commands with root privileges. The affected versions improperly handled user-controlled input in command strings, particularly within the check-plugins/restic-check plugin. The execution of these commands could be triggered via parameters, enabling a compromised monitoring account to bypass security measures. To mitigate this risk, users are advised to upgrade to linuxfabrik-lib version 5.0.0 and Linuxfabrik Monitoring Plugins version 6.0.0, which implement safeguards like avoiding shell execution for commands and validating positional values.

Affected Version(s)

lib < 5.0.0

monitoring-plugins < 6.0.0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.