<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 21:37:14 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-356990</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-356990</link>
      <description>EUVD-2026-356990</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-356990</guid>
    </item>
    <item>
      <title>fkie_cve-2026-55426</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-55426</link>
      <description>&lt;p&gt;linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations, and Linuxfabrik Monitoring Plugins uses those modules to run external monitoring commands. From the earliest affected releases until linuxfabrik-lib 5.0.0 and Linuxfabrik Monitoring Plugins 6.0.0, check plugins embedded user-controlled values in command strings passed to lib.shell.shell_exec(), which split strings at pipe characters and executed the resulting commands. In check-plugins/restic-check/restic-check, the --repo parameter could inject a pipe-delimited command into a constructed restic invocation, and sudo-authorized execution allowed a compromised nagios or icinga account to run that command as root. The shared library also accepted command strings and a shell parameter, while numerous plugins constructed external commands from attacker-influenced arguments. The fixes require argv lists, always use shell=False, remove pipe splitting, and reject option-like positional values through lib.shell.safe_cli_value(). These issues are fixed in linuxfabrik-lib 5.0.0 and Linuxfabrik Monitoring Plugins 6.0.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations, and Linuxfabrik Monitoring Plugins uses those modules to run external monitoring commands. From the earliest affected releases until linuxfabrik-lib 5.0.0 and Linuxfabrik Monitoring Plugins 6.0.0, check plugins embedded user-controlled values in command strings passed to lib.shell.shell_exec(), which split strings at pipe characters and executed the resulting commands. In check-plugins/restic-check/restic-check, the --repo parameter could inject a pipe-delimited command into a constructed restic invocation, and sudo-authorized execution allowed a compromised nagios or icinga account to run that command as root. The shared library also accepted command strings and a shell parameter, while numerous plugins constructed external commands from attacker-influenced arguments. The fixes require argv lists, always use shell=False, remove pipe splitting, and reject option-like positional values through lib.shell.safe_cli_value(). These issues are fixed in linuxfabrik-lib 5.0.0 and Linuxfabrik Monitoring Plugins 6.0.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-55426</guid>
    </item>
    <item>
      <title>GHSA-798h-hpph-m24j — Linuxfabrik Monitoring Plugins have local privilege escalation using embedded command</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-798h-hpph-m24j</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: linuxfabrik-lib&lt;/p&gt;
&lt;p&gt;### Summary
When a check plugin places user provided input inside a command which is passed to `shell_exec`, an attacker can abuse this to run arbitrary commands. This is mainly dangerous for plugins which are listed in the sudoers file, because this allows an attacker controlling the nagios user to get root privileges.&lt;/p&gt;
&lt;p&gt;### Details
An example for this is the `restic-check` plugin, where the `--repo` argument is placed inside the command argument of `shell_exec`. As an example, an attacker could use the `--repo` argument `|touch /root/nagios-was-here|`. The full restic command is assembled to the string `restic --json --repo=|touch /root/nagios-was-here| --password-file= check` before it is passed to `shell_exec`. `shell_exec` then splits the command up in three parts at the | boundaries and executes the parts separately, which also executes the embedded command `touch /root/nagios-was-here`.&lt;/p&gt;
&lt;p&gt;### PoC
This PoC shows how the nagios user can use this to create a file inside `/root`.
```
nagios@test-vm:/$ sudo /usr/lib64/nagios/plugins/restic-check --repo &amp;#39;|touch /root/nagios-was-here|&amp;#39;
```&lt;/p&gt;
&lt;p&gt;### Impact
The vulnerability is a local privilege escalation.&lt;/p&gt;
&lt;p&gt;### Fix&lt;/p&gt;
&lt;p&gt;#### Switch from | to an array
Remove the | split functionality. Instead, modify shell_exec to accept either a string or an array of strings. If an array is provided, the commands are chained together like they currently are when using |. If a string is provided, no split should be performed. You could also introduce a…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: linuxfabrik-lib&lt;/p&gt;
&lt;p&gt;### Summary
When a check plugin places user provided input inside a command which is passed to `shell_exec`, an attacker can abuse this to run arbitrary commands. This is mainly dangerous for plugins which are listed in the sudoers file, because this allows an attacker controlling the nagios user to get root privileges.&lt;/p&gt;
&lt;p&gt;### Details
An example for this is the `restic-check` plugin, where the `--repo` argument is placed inside the command argument of `shell_exec`. As an example, an attacker could use the `--repo` argument `|touch /root/nagios-was-here|`. The full restic command is assembled to the string `restic --json --repo=|touch /root/nagios-was-here| --password-file= check` before it is passed to `shell_exec`. `shell_exec` then splits the command up in three parts at the | boundaries and executes the parts separately, which also executes the embedded command `touch /root/nagios-was-here`.&lt;/p&gt;
&lt;p&gt;### PoC
This PoC shows how the nagios user can use this to create a file inside `/root`.
```
nagios@test-vm:/$ sudo /usr/lib64/nagios/plugins/restic-check --repo &amp;#39;|touch /root/nagios-was-here|&amp;#39;
```&lt;/p&gt;
&lt;p&gt;### Impact
The vulnerability is a local privilege escalation.&lt;/p&gt;
&lt;p&gt;### Fix&lt;/p&gt;
&lt;p&gt;#### Switch from | to an array
Remove the | split functionality. Instead, modify shell_exec to accept either a string or an array of strings. If an array is provided, the commands are chained together like they currently are when using |. If a string is provided, no split should be performed. You could also introduce a…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-798h-hpph-m24j</guid>
    </item>
    <item>
      <title>PYSEC-2026-2594 — Linuxfabrik Monitoring Plugins have local privilege escalation using embedded command</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-2594</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: linuxfabrik-lib&lt;/p&gt;
&lt;p&gt;### Summary
When a check plugin places user provided input inside a command which is passed to `shell_exec`, an attacker can abuse this to run arbitrary commands. This is mainly dangerous for plugins which are listed in the sudoers file, because this allows an attacker controlling the nagios user to get root privileges.&lt;/p&gt;
&lt;p&gt;### Details
An example for this is the `restic-check` plugin, where the `--repo` argument is placed inside the command argument of `shell_exec`. As an example, an attacker could use the `--repo` argument `|touch /root/nagios-was-here|`. The full restic command is assembled to the string `restic --json --repo=|touch /root/nagios-was-here| --password-file= check` before it is passed to `shell_exec`. `shell_exec` then splits the command up in three parts at the | boundaries and executes the parts separately, which also executes the embedded command `touch /root/nagios-was-here`.&lt;/p&gt;
&lt;p&gt;### PoC
This PoC shows how the nagios user can use this to create a file inside `/root`.
```
nagios@test-vm:/$ sudo /usr/lib64/nagios/plugins/restic-check --repo &amp;#39;|touch /root/nagios-was-here|&amp;#39;
```&lt;/p&gt;
&lt;p&gt;### Impact
The vulnerability is a local privilege escalation.&lt;/p&gt;
&lt;p&gt;### Fix&lt;/p&gt;
&lt;p&gt;#### Switch from | to an array
Remove the | split functionality. Instead, modify shell_exec to accept either a string or an array of strings. If an array is provided, the commands are chained together like they currently are when using |. If a string is provided, no split should be performed. You could also introduce a…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: linuxfabrik-lib&lt;/p&gt;
&lt;p&gt;### Summary
When a check plugin places user provided input inside a command which is passed to `shell_exec`, an attacker can abuse this to run arbitrary commands. This is mainly dangerous for plugins which are listed in the sudoers file, because this allows an attacker controlling the nagios user to get root privileges.&lt;/p&gt;
&lt;p&gt;### Details
An example for this is the `restic-check` plugin, where the `--repo` argument is placed inside the command argument of `shell_exec`. As an example, an attacker could use the `--repo` argument `|touch /root/nagios-was-here|`. The full restic command is assembled to the string `restic --json --repo=|touch /root/nagios-was-here| --password-file= check` before it is passed to `shell_exec`. `shell_exec` then splits the command up in three parts at the | boundaries and executes the parts separately, which also executes the embedded command `touch /root/nagios-was-here`.&lt;/p&gt;
&lt;p&gt;### PoC
This PoC shows how the nagios user can use this to create a file inside `/root`.
```
nagios@test-vm:/$ sudo /usr/lib64/nagios/plugins/restic-check --repo &amp;#39;|touch /root/nagios-was-here|&amp;#39;
```&lt;/p&gt;
&lt;p&gt;### Impact
The vulnerability is a local privilege escalation.&lt;/p&gt;
&lt;p&gt;### Fix&lt;/p&gt;
&lt;p&gt;#### Switch from | to an array
Remove the | split functionality. Instead, modify shell_exec to accept either a string or an array of strings. If an array is provided, the commands are chained together like they currently are when using |. If a string is provided, no split should be performed. You could also introduce a…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-2594</guid>
    </item>
  </channel>
</rss>
