CVE-2026-67433EPSS p1.0%
CVE-2026-67433CVE-2026-67433
Description
Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In version 6.0.0, the logfile check legacy database migration moved a predictable path from /tmp with os.rename() and allowed a local user controlling the plugin account to place a symlink that would be followed by sqlite3.connect() during a root-run check.
Scoring
| EPSS | 0.10% probability of exploitation · percentile 1.0% · 2026-10-05T12:00:23Z |
| Last modified | 2026-07-30 |