CVE-2026-34354 Details
Description
Akamai Guardicore Platform Agent (GPA) and Zero Trust Client on Linux and macOS allow TOCTOU-based local privilege escalation. The GPA service creates an IPC socket in the world-writable /tmp directory. It accepts unauthenticated IPC control messages. This enables a TOCTOU vulnerability in the HandleSaveLogs() function of the GPA service, by creating a log file and manipulating it into a symlink that points to the targeted path; this can allow an unprivileged local user to make arbitrary root-owned files world-writable. In addition, a diagnostic collection tool (gimmelogs) running with root privileges was vulnerable to command injection from the dbstore, offering a second privilege escalation vector. (On Windows, gimmelogs does not have command injection but does allow writing a ZIP archive to an unintended location.) This affects Akamai Guardicore Platform Agent 7.0 through 7.3.1 and Akamai Zero Trust Client 6.0 through 6.1.5.
A local privilege escalation vulnerability has been identified in Akamai Guardicore Platform Agent (GPA) versions 7.0 through 7.3.1 and Akamai Zero Trust Client versions 6.0 through 6.1.5, on Linux and macOS. The vulnerability arises from a time-of-check-to-time-of-use (TOCTOU) issue, where the GPA service creates an inter-process communication (IPC) socket in the world-writable /tmp directory, accepting unauthenticated IPC control messages. This allows an unprivileged local user to exploit the HandleSaveLogs() function by creating a log file and manipulating it into a symlink that points to a targeted path, potentially making arbitrary root-owned files world-writable. Additionally, the diagnostic collection tool gimmelogs, which runs with root privileges, was found to be vulnerable to command injection from the dbstore, providing another vector for privilege escalation.
Users of Akamai Guardicore Platform Agent on macOS and Linux should upgrade to the latest version. Instructions for downloading the updated version are available in the Akamai Guardicore Platform Agent documentation. Windows users can upgrade during their regular maintenance schedule.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 8, 2026CISA-ADP
Assessed May 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.akamai.com/blog/security-research/advisory-cve-2026-34354-guardicore-local-privilege-escalation | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-367 | Time-of-check Time-of-use (TOCTOU) Race Condition | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Akamai Guardicore Platform Agent | All versions |
CPE
Remediation
| |
| Akamai Zero Trust Client | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 8, 2026 | New CVE Received | [email protected] |
Volerion