Privilege Escalation Vulnerability in OpenVT Utility from Red Hat
CVE-2026-72693
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 11 August 2026
What is CVE-2026-72693?
The OpenVT utility from Red Hat has a vulnerability that allows an unprivileged process to perform a passwordless login as a privileged user under specific circumstances. The vulnerability arises from how the ownership of TTY device nodes is checked during user authentication, where the system incorrectly identifies the owner of the process. If the ownership test mistakenly recognizes the process as belonging to a privileged user, it allows an attacker to exploit the 'openvt -u' command to escalate their privileges potentially leading to unauthorized access to sensitive system areas.
Affected Version(s)
Red Hat Enterprise Linux 10 0:2.6.4-8.el10_2
Red Hat Enterprise Linux 9 0:2.4.0-12.el9_8
Red Hat Hardened Images 2.10.0-2.hum1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved