PT-2026-65901 · Linuxfabrik · Monitoring-Plugins

CVE-2026-67433

·

Published

2026-07-29

·

Updated

2026-07-29

CVSS v4.0

5.8

Medium

VectorAV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Linuxfabrik monitoring-plugins version 6.0.0
Description The logfile check legacy database migration uses os.rename() to move a predictable path from the /tmp directory. This allows a local user who controls the plugin account to create a symbolic link that is subsequently followed by the sqlite3.connect() function during a check executed with root privileges.
Recommendations As a temporary mitigation, restrict local user access to the plugin account or the /tmp directory to prevent the creation of symbolic links.

Exploit

Fix

Link Following

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67433
GHSA-W2GG-HX6W-24W3

Affected Products

Monitoring-Plugins