CVE-2026-88924High· 7.0▾ MidnightPoC availableA flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created private D-Bus sockets by calling the link-following chown() function on a pathname inside a user-controlled directory…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 38.5 · likelihood 0 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the assigning CNA record, not NVD.
Exploit-prediction probability, daily snapshots since Sep 11.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CVEORG
Exploit / PoC code exists
Last analysed / modified upstream
0.2%
A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created private D-Bus sockets by calling the link-following chown() function on a pathname inside a user-controlled directory. A local attacker can exploit this via a Time-of-Check Time-of-Use (TOCTOU) race condition and exchange the socket pathname with a symbolic link pointing to an arbitrary root-owned file (such as /etc/pam.d/su). The daemon subsequently follows the symlink and changes the ownership of the targeted root-owned file to the attacker's user ID. This allows an authenticated local attacker to modify critical system files, leading to a full local privilege escalation to root.
gvfs >= 1.48.1 < 1.62.0gvfs >= 1.48.1 < 1.60.3gvfs >= 1.48.1 < 1.58.5gvfs (all versions)gvfs (all versions)gvfs (all versions)gvfs (all versions)gvfs (all versions)Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
To mitigate this issue, adjust Polkit rules to require password authentication to start gvfsd-admin or remove execute permissions of the gvfsd-admin binary to prevent execution.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-23950High· 8.8node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3
CVE-2026-58014High· 7.3A flaw was found in GLib
CVE-2026-58011Medium· 6.5A flaw was found in GLib
CVE-2024-30088High· 7.0Windows Kernel Elevation of Privilege Vulnerability
CVE-2025-7425High· 7.8A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management
CVE-2026-55567High· 7.8BleachBit cleans files to free disk space and to maintain privacy