Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-75092— Leapp-repository: leapp-upgrade-el9toel10: leapp-upgrade-el9toel10: scan_mysql runs mysqld --validate-config as root and can load mysql-writable plugins

Quick assessment

Affected
Red Hat Red Hat Enterprise Linux 8
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

权限提升漏洞:在 提供的 包的 actor 中发现了权限提升漏洞。 在从 RHEL 9 升级到 RHEL 10 的过程中,该 actor 会以 root 身份在 Leapp actor 上下文中直接运行: 这一操作绕过了通常以 身份启动守护进程的标准 MySQL systemd 单元。 攻击路径: 以 OS 身份被攻陷的进程可以向 (该目录由 用户所有)写入: - 一个 version-2 的持久化配置文件( ); - 一个恶意的共享对象(shared object)。 该持久化配置可以将 设置为 ,并设置 (或相

CVSS 7.3 · High

Possible ATT&CK Techniques 1 AI

T1068 · Exploitation for Privilege Escalation
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-75092

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Leapp-repository: leapp-upgrade-el9toel10: leapp-upgrade-el9toel10: scan_mysql runs mysqld --validate-config as root and can load mysql-writable plugins
Source: CVE Program / CVE List V5
Vulnerability Description
A privilege escalation flaw was found in the scan_mysql actor of leapp-upgrade-el9toel10 (provided by leapp-repository). During RHEL 9 to RHEL 10 upgrades, the actor runs: mysqld --validate-config --log-error-verbosity=2 directly as root in the Leapp actor context, bypassing the packaged MySQL systemd unit that normally starts the daemon as User=mysql. A process compromised as the mysql OS identity can write a version-2 persisted configuration (mysqld-auto.cnf) and a malicious shared object into /var/lib/mysql (a directory owned by mysql). That persisted map can set plugin_dir to /var/lib/mysql and early_plugin_load (or related loader options such as plugin_load / plugin_load_add) so MySQL loads the attacker-controlled object during configuration validation. Plugin loading can reach dlopen() before MySQL’s runtime-user check and before plugin-symbol validation. When an administrator subsequently runs the documented Leapp preupgrade or upgrade workflow, attacker-controlled code can execute as UID 0 with a full capability set in an unconfined SELinux domain (unconfined_t). The attack does not require write access to the default system plugin path under /usr; redirecting plugin_dir via mysql-owned persisted state is sufficient. Ordinary SQL privileges alone (including highly privileged SQL accounts) are not a sufficient startpoint — OS-level execution as the mysql service identity is required, plus later administrator invocation of Leapp.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
带着不必要的权限执行
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Enterprise Linux 8 - cpe:/o:redhat:enterprise_linux:8
Red Hat Red Hat Enterprise Linux 9 - cpe:/o:redhat:enterprise_linux:9
Red Hat Red Hat OpenStack Platform 17.1 - cpe:/a:redhat:openstack:17.1

II. Public POCs for CVE-2026-75092

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-75092

登录查看更多情报信息。

Patches & Fixes for CVE-2026-75092 (1)

Vendor Advisories for CVE-2026-75092 (1)

Proof of Concept for CVE-2026-75092 (1)

Other References for CVE-2026-75092 (1)

Same Patch Batch · Red Hat · 2026-09-15 · 3 CVEs total

CVE-2026-81303 6.3 MEDIUM Hawtio-operator: hawtio-operator: routes/custom-host confused-deputy via spec.routehostnam
CVE-2026-81320 5.5 MEDIUM Hawtio-operator: hawtio-operator: tls private key written to operator log at debug level

IV. Related Vulnerabilities

V. Comments for CVE-2026-75092

No comments yet


Leave a comment