๐Ÿ” CVE Alert

CVE-2026-67433

UNKNOWN 0.0

Linuxfabrik monitoring-plugins: Symlink following in logfile legacy database migration

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In version 6.0.0, the logfile check legacy database migration moved a predictable path from /tmp with os.rename() and allowed a local user controlling the plugin account to place a symlink that would be followed by sqlite3.connect() during a root-run check.

CWE CWE-59 CWE-367
Vendor linuxfabrik
Product monitoring-plugins
Published Jul 29, 2026
Stay Ahead of the Next One

Get instant alerts for linuxfabrik monitoring-plugins

Be the first to know when new unknown vulnerabilities affecting linuxfabrik monitoring-plugins are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linuxfabrik / monitoring-plugins
6.0.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/Linuxfabrik/monitoring-plugins/security/advisories/GHSA-w2gg-hx6w-24w3 github.com: https://github.com/Linuxfabrik/monitoring-plugins/commit/6df1f574aa9dc6541e092f1ce482ecc1315cded0