CVE-2026-67433: CWE-59: Improper Link Resolution Before File Access ('Link Following') in Linuxfabrik monitoring-plugins
CVE-2026-67433 is a medium severity vulnerability in Linuxfabrik monitoring-plugins version 6.0.0. It involves improper link resolution before file access, where a local user controlling the plugin account can create a symbolic link in a predictable /tmp path. This symlink is followed by sqlite3.connect() during a root-run check, potentially leading to unauthorized file access or modification.
AI Analysis
Technical Summary
Linuxfabrik monitoring-plugins version 6.0.0 contains a CWE-59 (Improper Link Resolution Before File Access) vulnerability in the logfile check legacy database migration. The migration process moves a file using os.rename() from a predictable /tmp path. A local user with control over the plugin account can place a symbolic link at this location, which is then followed by sqlite3.connect() when the check runs with root privileges. This can lead to unintended file access or manipulation due to following the symlink.
Potential Impact
The vulnerability allows a local user with control over the plugin account to influence file operations performed by a root-run check. This can result in unauthorized file access or modification via symbolic link following, potentially compromising system integrity or confidentiality. The CVSS 4.0 score is 5.8 (medium severity), reflecting the requirement for local access and high attack complexity.
Mitigation Recommendations
No official patch or remediation is currently available for this vulnerability. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is released, restrict local access to the plugin account and avoid running the affected logfile check with root privileges if possible.
CVE-2026-67433: CWE-59: Improper Link Resolution Before File Access ('Link Following') in Linuxfabrik monitoring-plugins
Description
CVE-2026-67433 is a medium severity vulnerability in Linuxfabrik monitoring-plugins version 6.0.0. It involves improper link resolution before file access, where a local user controlling the plugin account can create a symbolic link in a predictable /tmp path. This symlink is followed by sqlite3.connect() during a root-run check, potentially leading to unauthorized file access or modification.
CVSS v4.0
Score 5.8medium
Affected software
Linuxfabrik
monitoring-plugins
pkg:github/linuxfabrik/monitoring-pluginsRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Linuxfabrik monitoring-plugins version 6.0.0 contains a CWE-59 (Improper Link Resolution Before File Access) vulnerability in the logfile check legacy database migration. The migration process moves a file using os.rename() from a predictable /tmp path. A local user with control over the plugin account can place a symbolic link at this location, which is then followed by sqlite3.connect() when the check runs with root privileges. This can lead to unintended file access or manipulation due to following the symlink.
Potential Impact
The vulnerability allows a local user with control over the plugin account to influence file operations performed by a root-run check. This can result in unauthorized file access or modification via symbolic link following, potentially compromising system integrity or confidentiality. The CVSS 4.0 score is 5.8 (medium severity), reflecting the requirement for local access and high attack complexity.
Mitigation Recommendations
No official patch or remediation is currently available for this vulnerability. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is released, restrict local access to the plugin account and avoid running the affected logfile check with root privileges if possible.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-07-29T15:07:24.991Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a6a69eb9c2644c7f809491a
Added to database: 07/29/2026, 21:00:27 UTC
Last enriched: 08/06/2026, 18:01:41 UTC
Last updated: 09/12/2026, 22:01:36 UTC
Views: 88
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.