Local Denial-of-Service Vulnerability in LACT by ilya-zlobintsev
CVE-2026-75038

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
25 August 2026

What is CVE-2026-75038?

The LACT application, developed by ilya-zlobintsev, contains a vulnerability related to UNIX symbolic link (symlink) following. This flaw can be exploited to achieve local denial-of-service, potentially disrupting service availability. The issue is present in all versions of LACT prior to 0.10.0, making it essential for users to assess their installations and apply necessary updates to mitigate impact.

Affected Version(s)

LACT Linux 0 <= 0.10.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.