---
id: CVE-2026-7867
title: A flaw was found in udisks2
summary: >-
  A flaw was found in udisks2. A local attacker with an active console session
  can exploit insufficient authorization checking on the 'as-user' option in the
  org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method. This allows the
  attacker…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-863
vendor: Red Hat
product: udisks
affected:
  - udisks >= 2.10.0 < 2.11.2
  - udisks2 (all versions)
  - udisks2 (all versions)
  - udisks2
  - udisks2
  - udisks2
published: '2026-08-06'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T08:17:12.173'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-7867'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:53435'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:64798'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2026-7867'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2466747'
    label: secalert@redhat.com
  - url: 'https://github.com/storaged-project/udisks/releases/tag/udisks-2.11.2'
    label: secalert@redhat.com
  - url: >-
      https://github.com/storaged-project/udisks/security/advisories/GHSA-j42g-v9jw-6ph3
    label: secalert@redhat.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-7867.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-7867'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-7867'
tags:
  - nvd
  - cve.org
  - exploit-available
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-08-08T02:06:34.276824Z'
epss: 0.00176
epssPercentile: 0.07378
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/azqzazq1/CVE-2026-7867-disk2root'
  checkedAt: '2026-09-24T07:53:18.030Z'
exploitAvailable: true
ingestedAt: '2026-09-08T15:33:26.951Z'
patched:
  - enterprise_linux_appstream_eus_v_10_0
  - enterprise_linux_appstream_v_10
  - enterprise_linux_codeready_linux_builder_eus_v_10_0
  - enterprise_linux_codeready_linux_builder_v_10
---

## Overview

A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization checking on the 'as-user' option in the org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method. This allows the attacker to spoof the 'as-user' parameter, mounting filesystems on behalf of arbitrary users, including privileged accounts. This can lead to local privilege escalation through mount point injection and manipulation of the mount namespace visible to privileged users.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2026:64798** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0), Red Hat Enterprise Linux CodeReady Linux Builder EUS (v. 10.0) · released 2026-09-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:64798)
- **RHSA-2026:53435** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10), Red Hat Enterprise Linux CodeReady Linux Builder (v. 10) · released 2026-08-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:53435)
