Race Condition Vulnerability in Cockpit Files by Red Hat
CVE-2026-91205

6MEDIUM

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
18 September 2026

What is CVE-2026-91205?

A security flaw in Cockpit Files allows a local unprivileged attacker to exploit a race condition during directory creation when the ownership assignment is taking place. By having access to a writable parent directory, the attacker can substitute a newly created directory with a symbolic link (symlink) before the ownership change operation (chown) is executed. This manipulation allows the attacker to redirect ownership changes to any arbitrary file, leading to potential exposure of sensitive information or unauthorized modifications to crucial files.

References

CVSS V3.1

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was discovered by AISLE Research and Found by AISLE in partnership with Red Hat.
.