Filesystem Path Exposure in Linuxfabrik Monitoring Plugins and linuxfabrik-lib
CVE-2026-73974

5.5MEDIUM

Key Information:

Vendor
CVE Published:
18 August 2026

What is CVE-2026-73974?

The linuxfabrik-lib, a library providing essential Python modules for various integrations, previously lacked proper path confinement when handling CSV arguments in the lib.lftest.test() function. This flaw allowed unauthorized access to filesystem paths, enabling attackers with control over the nagios or icinga account to exploit certain check plugins to reveal the contents of root-readable files. Affected versions prior to linuxfabrik-lib 6.1.0 and Linuxfabrik Monitoring Plugins 7.0.0 exposed sensitive information via various plugins by improperly filtering or allowing unauthorized read access. Recent updates have implemented fixes to confine read operations to specific plugin directories and mitigate these security risks.

Affected Version(s)

lib < 6.0.1

monitoring-plugins < 7.0.0

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.