What is CVE-2026-72694?
This flaw affects MRTG (Multi Router Traffic Grapher). When MRTG daemon starts as root and then drops privileges, a local low-privileged attacker can exploit a symlink following vulnerability in the PID file path. It is recommended to run MRTG as a non-root user and ensure restrictive permissions on the directory where the PID file is stored.
Azərbaycanca: Bu boşluq MRTG (Multi Router Traffic Grapher) alətinə aiddir. MRTG root istifadəçi kimi işə salınıb, daha sonra imtiyazları azaltdıqda, lokal, aşağı səviyyəli hücumçu PID fayl yolunda simvolik keçid (symlink) yaradaraq istismar edə bilər. Tövsiyə olunan tənzimləmə, MRTG-ni qeyri-root istifadəçi ilə işə salmaq və PID faylının yazıldığı qovluğun icazələrini yoxlamaqdır.
FAQ2
How is CVE-2026-72694 exploited in MRTG?
When MRTG starts as root and later drops privileges, a local low-privileged attacker can exploit a symlink following vulnerability in the PID file path.
What mitigation is recommended for CVE-2026-72694?
It is recommended to run MRTG as a non-root user and set restrictive permissions on the directory where the PID file is stored.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.