AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2018-10906

MEDIUM · CVSS 5.3 EPSS 1.41% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2018-07-24 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

Exhibit — Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

External Security References

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2018-10906
Severity
MEDIUM
CVSS
5.3
EPSS
1.41%
Linux

Original Filing — NVD Description

In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to a restriction bypass when SELinux is active. This allows non-root users to mount a FUSE file system with the 'allow_other' mount option regardless of whether 'user_allow_other' is set in the fuse configuration. An attacker may use this flaw to mount a FUSE file system, accessible by other users, and trick them into accessing files on that file system, possibly causing Denial of Service or other unspecified effects.