PT-2026-82539 · Dool · Dool

·

CVE-2026-56651

·

Published

2026-08-27

·

Updated

2026-08-28

CVSS v4.0

2.0

Low

VectorAV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Dool versions prior to 1.3.9
Description The application is susceptible to symlink following when the --devel flag is active. This occurs because the software opens a log file without the O NOFOLLOW flag, which is a system-level instruction that prevents the application from following symbolic links. A local attacker can create a symlink at the expected log file path that points to a sensitive file, leading the application to truncate and overwrite the target file with log data. This impact is increased if the application is executed with elevated privileges.
Recommendations Update to version 1.3.9 or later. As a temporary mitigation, avoid using the --devel flag.

Exploit

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56651

Affected Products

Dool