Privilege Escalation Vulnerability in Leapp for RHEL Upgrades by Red Hat
CVE-2026-75092

7.3HIGH

What is CVE-2026-75092?

A privilege escalation flaw exists in the Leapp upgrade process from RHEL 9 to RHEL 10. This vulnerability arises when the scan_mysql actor executes mysqld configurations directly as root, circumventing the MySQL daemon's standard operation under the mysql OS identity. An attacker can potentially exploit this by manipulating the MySQL configuration files and shared objects, allowing their code to run with elevated privileges. This situation could occur when an administrator uses the Leapp upgrade workflow after an attacker has altered the necessary configurations. By loading malicious plugins before MySQL enforces user validation, an attacker gains the ability to execute commands with full system rights, posing significant risks to system integrity and data security.

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Christopher Lusk (North Echo Security Research) for reporting this issue.
.