CVE-2026-23893Patch(opencryptoki_project / opencryptoki)

LOWCVSS 6.8 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch opencryptoki_project opencryptoki systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

openCryptoki is a PKCS#11 library and provides tooling for Linux and AIX. Versions 2.3.2 and above are vulnerable to symlink-following when running in privileged contexts. A token-group user can redirect file operations to arbitrary filesystem targets by planting symlinks in group-writable token directories, resulting in privilege escalation or data exposure. Token and lock directories are 0770 (group-writable for token users), so any token-group member can plant files and symlinks inside them. When run as root, the base code handling token directory file access, as well as several openCryptoki tools used for administrative purposes, may reset ownership or permissions on existing files inside the token directories. An attacker with token-group membership can exploit the system when an administrator runs a PKCS#11 application or administrative tool that performs chown on files inside the token directory during normal maintenance. This issue is fixed in commit 5e6e4b4, but has not been included in a released version at the time of publication.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-59

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • opencryptoki

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Peaked 1d ago at 1 mentions (2026-02-13); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
opencryptoki

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-13: 1Mentions · 2026-02-20: 1Patch / Workaround · 2026-02-13: 1Technical Details · 2026-02-20: 102-1302-20
Signal classification1 categories
Patch
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    #SUSE's latest security advisory (SUSE-2026-0581-1) addresses CVE-2026-23893 in openCryptoki. This moderate-severity, local privilege escalation flaw (CVSS 6.8) targets the PKCS#11 library on SLE 12 SP5. Read mroe: 👉 https://tinyurl.com/bdhjdhzn #Security https://t.co/rAg6dyfWT6

    Post summary

    SUSE’s latest advisory (SUSE‑2026‑0581‑1) addresses CVE‑2026‑23893, a moderate‑severity local privilege escalation vulnerability in openCryptoki; the advisory link likely contains patch details but no exploit or PoC is mentioned.

    0000032
    1.3K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Heads-up, #SUSE Linux community! A new advisory (SUSE-2026:0481-1) for openCryptoki addresses CVE-2026-23893. Read more: 👉 https://tinyurl.com/475myhvu #Security https://t.co/RMiDZphr27

    Post summary

    A new SUSE advisory (SUSE-2026:0481-1) has been issued for openCryptoki to address CVE-2026-23893, providing a link for further details.

    0000035
    1.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopencryptoki_projectopencryptoki---

Explore more