๐Ÿ” CVE Alert

CVE-2026-45254

UNKNOWN 0.0

Incorrect libcap_net limitation list manipulation

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the case of the cap_net service, when a key present in the old limit was omitted from the new limit, the missing key was treated as "allow any" instead of being rejected. In certain scenarios, an application that had previously restricted a subset of network operations could ask for a new limit that extended the permissions of the process.

CWE CWE-269
Vendor freebsd
Product freebsd
Published May 21, 2026
Stay Ahead of the Next One

Get instant alerts for freebsd freebsd

Be the first to know when new unknown vulnerabilities affecting freebsd freebsd are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

FreeBSD / FreeBSD
15.0-RELEASE < p9 14.4-RELEASE < p5 14.3-RELEASE < p14

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
security.freebsd.org: https://security.freebsd.org/advisories/FreeBSD-SA-26:24.cap_net.asc

Credits

Joshua Rogers of AISLE Research Team