AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2018-16588

HIGH · CVSS 7.8 EPSS 0.30%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2018-09-26 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.8. It affects Linux.

CVE
CVE-2018-16588
Severity
HIGH
CVSS
7.8
EPSS
0.30%
Linux

Original NVD Description

Privilege escalation can occur in the SUSE useradd.c code in useradd, as distributed in the SUSE shadow package through 4.2.1-27.9.1 for SUSE Linux Enterprise 12 (SLE-12) and through 4.5-5.39 for SUSE Linux Enterprise 15 (SLE-15). Non-existing intermediate directories are created with mode 0777 during user creation. Given that they are world-writable, local attackers might use this for privilege escalation and other unspecified attacks. NOTE: this would affect non-SUSE users who took useradd.c code from a 2014-04-02 upstream pull request; however, no non-SUSE distribution is known to be affected.

Related CVEs

Other vulnerabilities affecting the same vendor(s)