Local Privilege Escalation Vulnerability in MRTG by MRTG
CVE-2026-72694

7.1HIGH

What is CVE-2026-72694?

A vulnerability exists in MRTG where, if the daemon is initiated as a root user and later drops privileges, it falls prey to a symbolic link exploitation. Through this flaw, a low-privileged attacker can influence the symlink within the process ID (PID) file path. By doing so, the attacker can mislead the root process to alter the ownership of existing files, granting unauthorized access to sensitive files and allowing alterations to be made without consent.

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was discovered by Found by AISLE in partnership with Red Hat.
.