CVE-2026-26104 Details
Description
A flaw was found in the udisks storage management daemon that allows unprivileged users to back up LUKS encryption headers without authorization. The issue occurs because a privileged D-Bus method responsible for exporting encryption metadata does not perform a policy check. As a result, sensitive cryptographic metadata can be read and written to attacker-controlled locations. This weakens the confidentiality guarantees of encrypted storage volumes.
A vulnerability exists in the udisks storage management daemon, allowing unprivileged users to unauthorizedly back up LUKS encryption headers. This issue arises because a privileged D-Bus method intended for exporting encryption metadata lacks a proper policy check. Consequently, sensitive cryptographic metadata can be accessed and written to locations controlled by the attacker, undermining the confidentiality of encrypted storage volumes.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| redhat enterprise linux | 10.0 |
CPE
Remediation
| |
| freedesktop udisks | 2.0.0 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Mar 25, 2026 | CVE Modified | [email protected] |
| Mar 13, 2026 | CVE Modified | [email protected] |
| Mar 2, 2026 | CVE Modified | [email protected] |
| Feb 27, 2026 | Initial Analysis | [email protected] |
| Feb 25, 2026 | New CVE Received | [email protected] |