Linux ACL pre-2.4.0 Symlink Traversal in acl_get_file() & others - Priv Esc
CVE-2026-54369 Published on June 29, 2026
acl < 2.4.0 Symlink Traversal Privilege Escalation via libacl Functions
acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation.
Vulnerability Analysis
CVE-2026-54369 can be exploited with local system access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality and integrity, and no impact on availability.
Weakness Type
What is an insecure temporary file Vulnerability?
The software attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
CVE-2026-54369 has been classified to as an insecure temporary file vulnerability or weakness.
Products Associated with CVE-2026-54369
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2026-54369 are published in these products:
Affected Versions
acl project acl:- Before 2.4.0 is affected.
- Version 0:2.4.0-1.el10_2 and below * is unaffected.
- Version 0:2.4.0-1.el8_10 and below * is unaffected.
- Version 0:2.4.0-1.el9_8 and below * is unaffected.
- Version 1784821670 and below * is unaffected.
- Version 1784821750 and below * is unaffected.
- Version 2.4.0-0.1.hum1 and below * is unaffected.
- Version 1785704636 and below * is unaffected.
- Version 1784794818 and below * is unaffected.
- Version 1784794778 and below * is unaffected.
- Version 1784795112 and below * is unaffected.
- Version 1784794289 and below * is unaffected.
- Version 1784795076 and below * is unaffected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.