PT-2026-70085 · Mrtg+1 · Mrtg+1

·

CVE-2026-72694

·

Published

2026-08-11

·

Updated

2026-09-09

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions MRTG (affected versions not specified)
Description A flaw exists when the MRTG daemon is started as a root user and subsequently drops privileges. A local, low-privileged attacker can exploit a symbolic link (symlink) following vulnerability by pre-placing a symlink in the process ID (PID) file path. This allows the attacker to trick the root process into changing the ownership of an arbitrary existing file to the daemon user, potentially leading to local privilege escalation and unauthorized access to or modification of sensitive files.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:57596
ALSA-2026:57600
ALSA-2026:65832
AZL-95885
CVE-2026-72694
RHSA-2026:57596
RHSA-2026:57600

Affected Products

Mrtg
Rocky Linux