PT-2026-55478 · Debian+2 · Debian+2
CVE-2026-52817
·
Published
2026-07-02
·
Updated
2026-08-18
CVSS v4.0
8.4
High
| Vector | AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
monitoring-plugins (affected versions not specified)
Description
An issue exists in the Debian.sudoers file where the
apt-get command is permitted for the nagios user without enforcing specific arguments. This allows a user who has compromised the nagios account to perform a local privilege escalation by executing arbitrary arguments, such as using the APT::Update::Pre-Invoke option to spawn a root shell.Recommendations
Restrict the sudoers configuration to allow only the specific arguments required for the
apt-get command, such as /usr/bin/apt-get update --quiet 2, instead of allowing the command to be run with arbitrary arguments.Exploit
Fix
Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Nagios
Monitoring-Plugins