CVE-2026-67433: CWE-59: Improper Link Resolution Before File Access ('Link Following') in Linuxfabrik monitoring-plugins
CVE-2026-67433 is a medium severity vulnerability in Linuxfabrik monitoring-plugins version 6.0.0. It involves improper link resolution before file access, where a local user controlling the plugin account can create a symbolic link in a predictable /tmp path. This symlink is followed by sqlite3.connect() during a root-run check, potentially leading to unauthorized file access or modification.
AI Analysis
Technical Summary
Linuxfabrik monitoring-plugins version 6.0.0 contains a vulnerability due to improper link resolution (CWE-59) in its logfile check legacy database migration. The plugin moves a file using os.rename() to a predictable location in /tmp. A local user with control over the plugin account can place a symbolic link at this location. When the plugin runs with root privileges and calls sqlite3.connect(), it follows this symlink, which may lead to unintended file access or modification. The vulnerability is identified as CVE-2026-67433 with a CVSS 4.0 score of 5.8 (medium severity). No patch or official remediation is currently documented.
Potential Impact
A local user with control over the plugin account can exploit this vulnerability to cause the root-run check to follow a malicious symbolic link. This can result in unauthorized access or modification of files accessible by the root user during the sqlite3.connect() operation. The impact is limited by the requirement of local access and high attack complexity.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict local user access to the plugin account and avoid running the vulnerable plugin version with elevated privileges. Monitor vendor communications for updates on official fixes or workarounds.
CVE-2026-67433: CWE-59: Improper Link Resolution Before File Access ('Link Following') in Linuxfabrik monitoring-plugins
Description
CVE-2026-67433 is a medium severity vulnerability in Linuxfabrik monitoring-plugins version 6.0.0. It involves improper link resolution before file access, where a local user controlling the plugin account can create a symbolic link in a predictable /tmp path. This symlink is followed by sqlite3.connect() during a root-run check, potentially leading to unauthorized file access or modification.
CVSS v4.0
Score 5.8medium
Affected software
pkg:github/linuxfabrik/monitoring-pluginsRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Linuxfabrik monitoring-plugins version 6.0.0 contains a vulnerability due to improper link resolution (CWE-59) in its logfile check legacy database migration. The plugin moves a file using os.rename() to a predictable location in /tmp. A local user with control over the plugin account can place a symbolic link at this location. When the plugin runs with root privileges and calls sqlite3.connect(), it follows this symlink, which may lead to unintended file access or modification. The vulnerability is identified as CVE-2026-67433 with a CVSS 4.0 score of 5.8 (medium severity). No patch or official remediation is currently documented.
Potential Impact
A local user with control over the plugin account can exploit this vulnerability to cause the root-run check to follow a malicious symbolic link. This can result in unauthorized access or modification of files accessible by the root user during the sqlite3.connect() operation. The impact is limited by the requirement of local access and high attack complexity.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict local user access to the plugin account and avoid running the vulnerable plugin version with elevated privileges. Monitor vendor communications for updates on official fixes or workarounds.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-07-29T15:07:24.991Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a6a69eb9c2644c7f809491a
Added to database: 07/29/2026, 21:00:27 UTC
Last enriched: 07/29/2026, 21:00:56 UTC
Last updated: 07/29/2026, 21:55:05 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.