Sceawere

Vulnerability Detail

CVE-2026-7867UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

udisks2 Insufficient Authorization Privilege Escalation

Vulnerability Metadata

Severity
High
Score / CVSS
7.8
Creation Date
1d ago
Vendor
Red Hat
Product
Red Hat Enterprise Linux 10
Attack Type
Incorrect Authorization
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization checking on the 'as-user' option in the org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method. This allows the attacker to spoof the 'as-user' parameter, mounting filesystems on behalf of arbitrary users, including privileged accounts. This can lead to local privilege escalation through mount point injection and manipulation of the mount namespace visible to privileged users.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.8",
  "pubDate": "2026-08-06T22:18:33.100Z",
  "pubdate": "2026-08-06T22:18:33.100Z",
  "executiveSummary": "A local privilege escalation vulnerability has been identified in udisks2 concerning insufficient authorization checking on the 'as-user' option within a specific D-Bus method.\nThe vulnerability allows a local attacker with an active console session to manipulate parameter inputs, leading to unauthorized filesystem mounting operations on behalf of arbitrary users, including privileged accounts.\nThe impact of successful exploitation includes local privilege escalation, mount point injection, and the manipulation of mount namespaces visible to privileged users.\nThe risk implication is severe for multi-user systems where unprivileged local users possess active console access, potentially resulting in complete compromise of privileged accounts.\nAttacker capabilities require local access with an active console session, leveraging a design flaw in D-Bus method parameter validation rather than memory corruption.\nExploitation requirements necessitate an active local console session and the ability to interact with the system D-Bus interface to invoke the vulnerable method with spoofed parameters.",
  "technicalDetails": "The vulnerability resides within the udisks2 service, specifically in the handling of the org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method.\nThe root cause of the flaw is insufficient authorization checking and input validation applied to the 'as-user' option provided during the method invocation.\nBecause the authorization checks fail to adequately verify whether the caller possesses the necessary permissions to execute the mount operation as the specified target user, a local attacker can spoof the 'as-user' parameter.\nThe attack flow proceeds as follows: First, the local attacker establishes an active console session on the host system. Second, the attacker formulates a D-Bus message targeting the org.freedesktop.UDisks2.Filesystem.Mount() method. Third, the attacker populates the 'as-user' parameter within the D-Bus method call with the identity of a privileged account, such as root. Fourth, due to the lack of stringent validation and authorization verification within udisks2, the daemon processes the request and mounts the specified filesystem on behalf of the arbitrary privileged user.\nPost-exploitation impact includes mount point injection and the manipulation of the mount namespace visible to privileged users, which can be leveraged to achieve arbitrary code execution or escalate privileges to the targeted user account.\nThe vulnerable component is the Filesystem interface implementation within udisks2 responsible for processing D-Bus mount requests.\nAuthentication and privilege requirements are minimal from the initial standpoint, requiring only a local attacker with an active console session.\nNetwork exposure is absent, as the attack vector is strictly local via the system D-Bus daemon."
}
CVE-2026-7867: udisks2 Insufficient Authorization Privilege Escalation (HIGH Severity, CVSS: 7.8) - Sceawere