Linuxfabrik 监控插件为 Icinga、Nagios 及相关系统提供监控插件。在 7.0.0 版本之前, 接受自由格式的 路径,并通过随附的 Nagios 或 Icinga 的 sudoers 允许列表以 root 权限打开该文件,而未将解析后的路径限制在 目录下。攻击者如果控制了监控账户,可以选择一个 root 可读的文件(如 ),并将 设置为 ,同时保持 为 ,从而将每一行非空内容收集到 中,并通过 返回。漏洞流程将扩展后的 直接传递给 函数,且既没有进行真实路径的边界检查,也没有通过白名单进行保护。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linuxfabrik | monitoring-plugins | < 7.0.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Linuxfabrik | monitoring-plugins | < 7.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-55426 | 7.8 HIGH | linuxfabrik-lib: Local privilege escalation using embedded command |
| CVE-2026-52817 | 7.0 HIGH | Linuxfabrik Monitoring Plugins Sudoers: /usr/bin/apt-get arguments allow privilege escalat |
| CVE-2026-73974 | 5.5 MEDIUM | linuxfabrik-lib: Arbitrary root file read via live --test argument (lib.lftest) across sud |
| CVE-2026-53759 | 2.0 LOW | linuxfabrik-lib: Insecure creation of SQLite databases |
No comments yet