CVE-2026-7867 Details
Description
A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization checking on the 'as-user' option in the org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method. This allows the attacker to spoof the 'as-user' parameter, mounting filesystems on behalf of arbitrary users, including privileged accounts. This can lead to local privilege escalation through mount point injection and manipulation of the mount namespace visible to privileged users.
A local privilege escalation vulnerability has been identified in udisks2, specifically in versions 2.10.0 and later. The issue arises from inadequate authorization checks on the 'as-user' option in the org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method. This flaw allows a local attacker with an active console session to spoof the 'as-user' parameter, enabling the mounting of filesystems on behalf of any user, including those with privileged accounts. The exploitation of this vulnerability can lead to unauthorized manipulation of the mount namespace for privileged users and injection of malicious content into mount points, potentially escalating privileges.
Users can upgrade to udisks2 version 2.11.2, which addresses this vulnerability by implementing the necessary authorization checks. The updated version is available for download from the Red Hat Enterprise Linux 10 repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 8, 2026 | CVE Modified | [email protected] |
| Aug 26, 2026 | CVE Modified | [email protected] |
| Aug 11, 2026 | CVE Modified | [email protected] |
| Aug 8, 2026 | CVE Modified | CISA-ADP |
| Aug 6, 2026 | New CVE Received | [email protected] |