OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-93786

HIGH · CVSS 8.1 EPSS 0.34%

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

A vulnerability in the Linux kernel affects the ksmbd module, which improperly handles the inheritance of POSIX ACL masks during the creation of child objects. This flaw can lead to unintended widening of effective permissions, potentially allowing unauthorized access to SMB objects. Organizations utilizing Linux systems with SMB services should prioritize addressing this issue to maintain proper access controls and prevent potential security breaches.

CVE
CVE-2026-93786
Severity
HIGH
CVSS
8.1
EPSS
0.34%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: ksmbd: preserve VFS inherited POSIX ACL mask The VFS initializes a child's POSIX ACL from the parent's default ACL and the requested creation mode. Do not mutate the parent ACL or overwrite the child's VFS-computed access and default ACLs afterwards. This preserves restrictive ACL_MASK entries and prevents SMB object creation from widening effective permissions.