Threats Tagged 'cve-2026-55086'
View all threats tagged with 'cve-2026-55086'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-55086'
Click on any threat for detailed analysis and mitigation recommendations
ep_etherpad-lite: Import/export uses Math.random() for temp file paths; predictable paths on shared /tmp enable symlink-based file overwrite (CVE-2026-55086)CVE-2026-55086 0 ep_etherpad-lite versions prior to 3.1.0 use a non-cryptographically secure random number generator (Math.random()) to create temporary file paths in a shared /tmp directory. This predictability allows a local attacker with access to the host to pre-create symbolic links at these paths, potentially causing the Etherpad process to overwrite arbitrary files it can write to, including sensitive files if running with elevated privileges. The vulnerability requires local access and the ability to predict temp filenames but can lead to local file overwrite. The issue is patched in version 3.1.0 by replacing Math.random() with a cryptographically secure random number generator. Join the discussion | GCVE Database | 08/13/2026, 14:11:07 UTC Added: 08/13/2026, 17:48:32 UTC |
Showing 1 to 1 of 1 result