Privilege Escalation Vulnerability in OpenVT Utility from Red Hat
CVE-2026-72693

7.8HIGH

What is CVE-2026-72693?

The OpenVT utility from Red Hat has a vulnerability that allows an unprivileged process to perform a passwordless login as a privileged user under specific circumstances. The vulnerability arises from how the ownership of TTY device nodes is checked during user authentication, where the system incorrectly identifies the owner of the process. If the ownership test mistakenly recognizes the process as belonging to a privileged user, it allows an attacker to exploit the 'openvt -u' command to escalate their privileges potentially leading to unauthorized access to sensitive system areas.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was discovered by Found by AISLE in partnership with Red Hat.
.