PT-2026-68821 · Udisks2+2 · Udisks2+2

CVE-2026-7867

·

Published

2026-04-21

·

Updated

2026-08-31

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions udisks2 (affected versions not specified)
Description Insufficient authorization checking in the org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method allows a local attacker with an active console session to spoof the as-user parameter. This enables the attacker to mount filesystems on behalf of arbitrary users, including privileged accounts, potentially leading to local privilege escalation via mount point injection and manipulation of the mount namespace visible to privileged users.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

LPE

Improper Privilege Management

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:53435
BDU:2026-14235
CVE-2026-7867
GHSA-J42G-V9JW-6PH3
OESA-2026-3460
OESA-2026-3461
OESA-2026-3462
OPENSUSE-SU-2026:11501-1
OPENSUSE-SU-2026:21704-1
RHSA-2026:53435
SUSE-SU-2026:23405-1
USN-8701-1

Affected Products

Linuxmint
Ubuntu
Udisks2