CVE-2026-67433
Linuxfabrik monitoring-plugins: Symlink following in logfile legacy database migration
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In version 6.0.0, the logfile check legacy database migration moved a predictable path from /tmp with os.rename() and allowed a local user controlling the plugin account to place a symlink that would be followed by sqlite3.connect() during a root-run check.
| CWE | CWE-59 CWE-367 |
| Vendor | linuxfabrik |
| Product | monitoring-plugins |
| Published | Jul 29, 2026 |
Stay Ahead of the Next One
Get instant alerts for linuxfabrik monitoring-plugins
Be the first to know when new unknown vulnerabilities affecting linuxfabrik monitoring-plugins are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Linuxfabrik / monitoring-plugins
6.0.0