PT-2026-95635 · Unknown · Cockpit-Files

·

CVE-2026-91203

·

Published

2026-09-18

·

Updated

2026-09-18

CVSS v3.1

6.0

Medium

VectorAV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions cockpit-files (affected versions not specified)
Description A timing issue, known as a symlink race condition, exists during privileged file operations such as changing file ownership or permissions. A local attacker can manipulate directory entries to redirect these operations to unintended files. This may result in unauthorized changes to file ownership and permissions on arbitrary files, potentially compromising system integrity and availability by altering system or application states or rendering services unusable. A symlink race condition occurs when a program checks a file's properties and then performs an action on it, but an attacker replaces the file with a symbolic link to another file in the brief interval between the check and the action.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-91203

Affected Products

Cockpit-Files