CVE-2026-54369Disclosure

LOWCVSS 8.4 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-59

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-06-29); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-06-29: 1Mentions · 2026-06-30: 1Patch / Workaround · 2026-06-30: 1Technical Details · 2026-06-29: 1Technical Details · 2026-06-30: 106-2906-30
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-06-291
Disclosure1
2026-06-301
Patch1
Full discourse2 posts
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH severity CVE-2026-54369 (CVSS 7.1) affects acl <2.4.0. Symlink traversal in libacl pathname functions enables local privilege escalation. Patch immediately to v2.4.0+. #CVE #Vulnerability #PatchNow #ThreatIntel #CyberSecurity https://t.co/c0Z9Y2uKSE

    Post summary

    The tweet announces a high‑severity CVE (CVE‑2026‑54369) affecting libacl versions below 2.4.0, notes a symlink traversal flaw that allows local privilege escalation, and urges users to patch to version 2.4.0 or newer.

    0000046
    55 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-54369 Symlink Traversal Vulnerability in ACL Before Version 2.4... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-54369 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The post merely announces a symlink traversal vulnerability (CVE‑2026‑54369) in ACL prior to version 2.4 and directs readers to an external page for further details, providing no proof of concept, exploit code, or evidence of active exploitation.

    0000092
    4.1K followersView on X

Explore more