AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-72694

HIGH · CVSS 7.1 EPSS 0.13% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

A vulnerability exists in the MRTG daemon that allows local, low-privileged attackers to exploit a symlink following issue when the daemon is started as a root user. By manipulating the symlink in the process ID (PID) file path, attackers can escalate privileges, potentially gaining unauthorized access to sensitive files. Organizations using MRTG should prioritize patching this vulnerability to mitigate the risk of local privilege escalation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-72694
Severity
HIGH
CVSS
7.1
EPSS
0.13%

Original NVD Description

A flaw was found in MRTG. When the MRTG daemon is started as a root user and subsequently drops privileges, a local, low-privileged attacker can exploit a symbolic link (symlink) following vulnerability. By influencing or pre-placing a symlink in the process ID (PID) file path, the attacker can trick the root process into changing the ownership of an arbitrary existing file to the daemon user. This can lead to local privilege escalation, allowing unauthorized access to or modification of sensitive files.