Threats Tagged 'cve-2026-91142'
View all threats tagged with 'cve-2026-91142'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-91142'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-91142 is an integer overflow vulnerability in the do_lastlog() function of Cockpit on ILP32 builds. A low-privileged authenticated user with a large User ID can cause an offset wraparound, enabling unauthorized reads and writes to other users' lastlog records. This flaw may disclose or alter sensitive login accounting data but does not allow code execution or privilege escalation. The vulnerability has a low CVSS score of 3.6 and requires local access with high attack complexity. Join the discussion | GCVE Database | 09/18/2026, 16:44:09 UTC Added: 09/19/2026, 01:27:39 UTC |
A flaw was found in Cockpit. An integer overflow vulnerability in the `do_lastlog()` function, specifically in the offset calculation for `lastlog` entries on ILP32 (Integer, Long, Pointer 32-bit) builds, can be exploited. A low-privileged authenticated user with a specially provisioned large User ID (UID) can cause the computed offset to wrap around. This allows the user to perform unauthorized reads and writes to other users' `lastlog` records, potentially disclosing or altering sensitive login accounting information. Join the discussion | CVE Database V5 | 09/18/2026, 16:44:09 UTC Added: 09/18/2026, 16:47:05 UTC |
Showing 1 to 2 of 2 results