SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-59676

MEDIUM · CVSS 5.8 EPSS 0.09%

Source: NVD + CISA KEV + EPSS · Published 2026-07-23 · Last synced 2026-08-22

CyberRota Analysis

AI-Generated

A Time-of-check Time-of-use (TOCTOU) race condition vulnerability in the seunshare component of the policycoreutils package allows unconfined SELinux users to delete arbitrary root-owned files. This could lead to unauthorized file manipulation and potential privilege escalation. Administrators of Linux systems utilizing policycoreutils versions up to 3.10 should prioritize addressing this vulnerability to mitigate security risks.

CVE
CVE-2026-59676
Severity
MEDIUM
CVSS
5.8
EPSS
0.09%
Linux

Original NVD Description

A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in seunshare of selinux policycoreutils allows a user calling seunshare that is running in the unconfined SELinux domain to delete arbitrary root-owned files, This issue affects policycoreutils through 3.10.