{"id":"CVE-2026-7867","title":"A flaw was found in udisks2","summary":"A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization checking on the 'as-user' option in the org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method. This allows the attacker…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-863"],"vendor":"Red Hat","product":"udisks","affected":["udisks >= 2.10.0 < 2.11.2","udisks2 (all versions)","udisks2 (all versions)","udisks2","udisks2","udisks2"],"published":"2026-08-06","updated":"2026-09-08","sourceUpdated":"2026-09-08T08:17:12.173","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-7867","references":[{"url":"https://access.redhat.com/errata/RHSA-2026:53435","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:64798","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2026-7867","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2466747","label":"secalert@redhat.com"},{"url":"https://github.com/storaged-project/udisks/releases/tag/udisks-2.11.2","label":"secalert@redhat.com"},{"url":"https://github.com/storaged-project/udisks/security/advisories/GHSA-j42g-v9jw-6ph3","label":"secalert@redhat.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-7867.json"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-7867"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-7867"}],"tags":["nvd","cve.org","exploit-available","csaf","vex","red-hat"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-08-08T02:06:34.276824Z"},"epss":0.00176,"epssPercentile":0.07385,"exploits":{"github":1,"githubRepos":["https://github.com/azqzazq1/CVE-2026-7867-disk2root"],"checkedAt":"2026-09-23T07:14:51.759Z"},"exploitAvailable":true,"ingestedAt":"2026-09-08T15:33:26.951Z","patched":["enterprise_linux_appstream_eus_v_10_0","enterprise_linux_appstream_v_10","enterprise_linux_codeready_linux_builder_eus_v_10_0","enterprise_linux_codeready_linux_builder_v_10"],"slug":"CVE-2026-7867","body":"## Overview\n\nA flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization checking on the 'as-user' option in the org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method. This allows the attacker to spoof the 'as-user' parameter, mounting filesystems on behalf of arbitrary users, including privileged accounts. This can lead to local privilege escalation through mount point injection and manipulation of the mount namespace visible to privileged users.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **RHSA-2026:64798** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0), Red Hat Enterprise Linux CodeReady Linux Builder EUS (v. 10.0) · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:64798)\n- **RHSA-2026:53435** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10), Red Hat Enterprise Linux CodeReady Linux Builder (v. 10) · released 2026-08-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:53435)","depth":"midnight","depthScore":55,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":12,"ransomware":0},"changes":[]}