CVE-2026-73973: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Linuxfabrik monitoring-plugins
Linuxfabrik monitoring-plugins prior to version 7.0.0 contain a path traversal vulnerability in the logfile check plugin. The plugin accepts a free-form --filename argument and opens the specified file as root without restricting the path to /var/log. This allows an attacker with control over the monitoring account to read arbitrary root-readable files such as /etc/shadow. The issue is fixed in version 7.0.0 by confining paths to documented log roots and resolving symlinks and parent-directory traversal before access.
AI Analysis
Technical Summary
The Linuxfabrik monitoring-plugins package, used for Icinga, Nagios, and related systems, has a CWE-22 path traversal vulnerability in the logfile check plugin prior to version 7.0.0. The plugin accepts a --filename parameter that is opened as root without confinement to /var/log. This allows an attacker with monitoring account privileges to specify arbitrary root-readable files (e.g., /etc/shadow) and have their contents read and returned. The vulnerability arises because the expanded scan_path is passed directly to open() without real-path containment or allowlist checks. The fix in version 7.0.0 confines paths to documented log roots and resolves symlinks and parent-directory traversal before checking containment.
Potential Impact
An attacker with control over the monitoring account can exploit this vulnerability to read arbitrary root-readable files on the system, potentially exposing sensitive information such as password hashes from /etc/shadow. The vulnerability does not allow modification or denial of service but compromises confidentiality.
Mitigation Recommendations
Upgrade to Linuxfabrik monitoring-plugins version 7.0.0 or later, where this path traversal vulnerability is fixed by restricting file paths to allowed log directories and resolving symlinks and traversal sequences before file access. No other mitigations are indicated.
CVE-2026-73973: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Linuxfabrik monitoring-plugins
Description
Linuxfabrik monitoring-plugins prior to version 7.0.0 contain a path traversal vulnerability in the logfile check plugin. The plugin accepts a free-form --filename argument and opens the specified file as root without restricting the path to /var/log. This allows an attacker with control over the monitoring account to read arbitrary root-readable files such as /etc/shadow. The issue is fixed in version 7.0.0 by confining paths to documented log roots and resolving symlinks and parent-directory traversal before access.
CVSS v3.1
Score 5.5medium
Affected software
Linuxfabrik
monitoring-plugins
pkg:github/linuxfabrik/monitoring-pluginsRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linuxfabrik monitoring-plugins package, used for Icinga, Nagios, and related systems, has a CWE-22 path traversal vulnerability in the logfile check plugin prior to version 7.0.0. The plugin accepts a --filename parameter that is opened as root without confinement to /var/log. This allows an attacker with monitoring account privileges to specify arbitrary root-readable files (e.g., /etc/shadow) and have their contents read and returned. The vulnerability arises because the expanded scan_path is passed directly to open() without real-path containment or allowlist checks. The fix in version 7.0.0 confines paths to documented log roots and resolves symlinks and parent-directory traversal before checking containment.
Potential Impact
An attacker with control over the monitoring account can exploit this vulnerability to read arbitrary root-readable files on the system, potentially exposing sensitive information such as password hashes from /etc/shadow. The vulnerability does not allow modification or denial of service but compromises confidentiality.
Mitigation Recommendations
Upgrade to Linuxfabrik monitoring-plugins version 7.0.0 or later, where this path traversal vulnerability is fixed by restricting file paths to allowed log directories and resolving symlinks and traversal sequences before file access. No other mitigations are indicated.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-08-13T21:42:04.044Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a84d00bc6e8be0332c73b09
Added to database: 08/18/2026, 21:35:07 UTC
Last enriched: 09/11/2026, 10:33:12 UTC
Last updated: 10/02/2026, 02:46:06 UTC
Views: 65
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.