PT-2026-78229 · Unknown · Linuxfabrik-Lib+1

CVE-2026-73974

·

Published

2026-08-18

·

Updated

2026-08-19

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions linuxfabrik-lib versions prior to 6.1.0 Linuxfabrik Monitoring Plugins versions prior to 7.0.0
Description The lib.lftest.test() function in linuxfabrik-lib improperly handles the --test CSV argument by treating its first or second element as a filesystem path and returning the file contents as simulated standard output or standard error without path confinement. Because this hidden argument is accepted by sudo-authorized plugins, an attacker with control over the nagios or icinga account can disclose the contents of root-readable files. Specifically, the check-plugins/deb-updates/deb-updates plugin with QUERY=1 allows full disclosure of root-readable files, while approximately 22 other plugins may expose filtered content or act as an oracle for root file existence and readability. Additionally, check-plugins/network-bonding/network-bonding and check-plugins/openstack-swift-stat/openstack-swift-stat contain direct read paths that bypass the helper function.
Recommendations Update linuxfabrik-lib to version 6.1.0. Update Linuxfabrik Monitoring Plugins to version 7.0.0.

Exploit

Fix

Improper Privilege Management

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73974
GHSA-RH9C-RQVG-F7PR
PYSEC-2026-3682

Affected Products

Linuxfabrik Monitoring Plugins
Linuxfabrik-Lib