PT-2026-78229 · Unknown · Linuxfabrik-Lib+1
CVE-2026-73974
·
Published
2026-08-18
·
Updated
2026-08-19
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
linuxfabrik-lib versions prior to 6.1.0
Linuxfabrik Monitoring Plugins versions prior to 7.0.0
Description
The
lib.lftest.test() function in linuxfabrik-lib improperly handles the --test CSV argument by treating its first or second element as a filesystem path and returning the file contents as simulated standard output or standard error without path confinement. Because this hidden argument is accepted by sudo-authorized plugins, an attacker with control over the nagios or icinga account can disclose the contents of root-readable files. Specifically, the check-plugins/deb-updates/deb-updates plugin with QUERY=1 allows full disclosure of root-readable files, while approximately 22 other plugins may expose filtered content or act as an oracle for root file existence and readability. Additionally, check-plugins/network-bonding/network-bonding and check-plugins/openstack-swift-stat/openstack-swift-stat contain direct read paths that bypass the helper function.Recommendations
Update linuxfabrik-lib to version 6.1.0.
Update Linuxfabrik Monitoring Plugins to version 7.0.0.
Exploit
Fix
Improper Privilege Management
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linuxfabrik Monitoring Plugins
Linuxfabrik-Lib