CVE-2026-34354Disclosure

LOWCVSS 7.4 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Akamai Guardicore Platform Agent (GPA) and Zero Trust Client on Linux and macOS allow TOCTOU-based local privilege escalation. The GPA service creates an IPC socket in the world-writable /tmp directory. It accepts unauthenticated IPC control messages. This enables a TOCTOU vulnerability in the HandleSaveLogs() function of the GPA service, by creating a log file and manipulating it into a symlink that points to the targeted path; this can allow an unprivileged local user to make arbitrary root-owned files world-writable. In addition, a diagnostic collection tool (gimmelogs) running with root privileges was vulnerable to command injection from the dbstore, offering a second privilege escalation vector. (On Windows, gimmelogs does not have command injection but does allow writing a ZIP archive to an unintended location.) This affects Akamai Guardicore Platform Agent 7.0 through 7.3.1 and Akamai Zero Trust Client 6.0 through 6.1.5.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-367

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-05-08); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-08: 2Mentions · 2026-05-10: 1Technical Details · 2026-05-08: 2Technical Details · 2026-05-10: 105-0805-10
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-082
Disclosure2
2026-05-101
Disclosure1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-34354 Akamai Guardicore Platform Agent (GPA) and Zero Trust Client on Linux and macOS allow TOCTOU-based local privilege escalation. The GPA service creates an IPC socket i… https://www.cve.org/CVERecord?id=CVE-2026-34354

    Post summary

    The snippet reports a new CVE describing a TOCTOU-based local privilege escalation in Akamai Guardicore products, with no mention of PoC, exploit code, active exploitation, or patch availability.

    00000211
    57.5K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-34354 Akamai Guardicore Platform Agent (GPA) and Zero Trust Client on Linux and macOS allow TOCTOU-based local privilege esca… CVSS 7.4 Full analysis → https://sec.kaitan.id/cves/CVE-2026-34354 #Linux #CyberSecurity #InfoSec

    Post summary

    The tweet announces CVE-2026-34354, a high‑severity TOCTOU local privilege escalation in Akamai Guardicore Platform Agent and Zero Trust Client, and provides a link to a full analysis without citing a PoC or patch.

    0000049
    90 followersView on X
  • ChangeWatch@changewatchdev
    Disclosure

    Linode Guardicore Windows agent vulnerable to LPE (CVE-2026-34354) If you run the Akamai Guardicore Platform Agent on Windows hosts (including Linode VMs), this CVE describes a local privilege escalation that can allow a low-privilege user… Read more → http://changewatch.dev/explore/d052d1bc-c0c7-4687-abaf-af856f0a79e3

    Post summary

    The post announces the discovery of CVE-2026-34354, a local privilege escalation flaw affecting the Guardicore Windows agent, but does not provide any PoC, exploit, or patch details.

    0000038
    2 followersView on X

Explore more