Local Privilege Escalation Vulnerability in Cockpit Files by Red Hat
CVE-2026-91202
6.1MEDIUM
What is CVE-2026-91202?
A vulnerability exists in Cockpit Files that permits a low-privileged local user to exploit directory symlinks. By crafting a directory with a symlink and utilizing the 'Paste as owner' feature, an attacker can change file ownership to unauthorized users. This alteration risks compromising data integrity and may lead to unauthorized read access if sensitive files are exposed. The exploitation of this vulnerability requires user participation in selecting a non-original file owner during paste operations, making it critical for users to understand potential risks.
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This issue was discovered by Found by AISLE in partnership with Red Hat.