CVE-2026-72694

NameCVE-2026-72694
DescriptionA flaw was found in MRTG. When the MRTG daemon is started as a root user and subsequently drops privileges, a local, low-privileged attacker can exploit a symbolic link (symlink) following vulnerability. By influencing or pre-placing a symlink in the process ID (PID) file path, the attacker can trick the root process into changing the ownership of an arbitrary existing file to the daemon user. This can lead to local privilege escalation, allowing unauthorized access to or modification of sensitive files.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
mrtg (PTS)bullseye2.17.7-2+deb11u1vulnerable
bookworm2.17.10-5+deb12u2vulnerable
trixie2.17.10-13+deb13u1vulnerable
forky, sid2.17.10-14vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
mrtgsource(unstable)(unfixed)

Notes

https://bugzilla.redhat.com/show_bug.cgi?id=2460973
Fixed by: https://github.com/oetiker/mrtg/commit/30e19216bfadc0148f347cb0a42fd5e2016e6269

Search for package or bug name: Reporting problems