SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-46388

MEDIUM · CVSS 4.4 EPSS 0.09% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-10 · Last synced 2026-08-09

CyberRota Analysis

AI-Generated

An unprivileged attacker can exploit a permissions vulnerability in osquery prior to version 5.23.1 to read sensitive files during the file carving process, as in-progress carve directories lack private permissions. This could lead to unauthorized access to sensitive local files if the carve targets a directory controlled by the attacker. Organizations using osquery should prioritize upgrading to version 5.23.1 to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-46388
Severity
MEDIUM
CVSS
4.4
EPSS
0.09%

Original NVD Description

osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. Prior to 5.23.1, an unprivileged attacker can read the contents of an osquery file carve until the carve completes and the temporary files are deleted because in-progress carve directories are not created with private permissions. If the carve targets a directory that the attacker controls, arbitrary file reads are possible, such as sensitive local files. This issue is fixed in version 5.23.1.