Local Privilege Escalation in Udisks2 by Red Hat
CVE-2026-7867
7.8HIGH
What is CVE-2026-7867?
A security flaw in Udisks2 allows a local attacker with an active console session to exploit insufficient authorization on the 'as-user' option in the D-Bus method org.freedesktop.UDisks2.Filesystem.Mount(). This exploitation enables the attacker to spoof the 'as-user' parameter, potentially allowing for arbitrary filesystem mounts on behalf of other users, including those with elevated privileges. Consequently, this manipulation can lead to local privilege escalation, where an attacker could inject mount points and alter the mount namespace accessible to privileged users.
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Azizcan DaĹźtan (azqzazq1) and Ă–zlem Ozan (oz7oz7) for reporting this issue.