High CVSS 7.1
CVE-2026-72694
NVD analysis in progress
A flaw was found in MRTG. When the MRTG daemon is started as a root user and subsequently drops privileges, a local, low-privileged attacker can exploit a symbolic link (symlink) following vulnerability. By influencing or pre-placing a symlink in the process ID (PID) file path, the attacker can trick the root process into changing the ownership of an arbitrary existing file to the daemon user. This can lead to local privilege escalation, allowing unauthorized access to or modification of sensitive files.
What this means
- Exposure
- Exploitable with local access to the machine, with an ordinary user account and with no action from the victim.
- Impact
- An attacker can read sensitive data and modify or destroy data.
- Weakness
- The program follows a symbolic link without checking its target, so a local attacker can redirect it to a sensitive file.
- Likelihood
- Its EPSS score stays low: nothing points to imminent exploitation, which is no reason to leave it unpatched.
What to doFold into the next patch cycle.
Read automatically from the CVSS vector, the weakness type (CWE) and the EPSS score. The technical description above remains the one published by NIST.