What is CVE-2026-73585?
A vulnerability (CVE-2026-73585) has been found in sblim-cmpi-base. Insecure temporary file creation in the provider registration scripts allows a local unprivileged user to redirect privileged writes to an arbitrary file via a symlink attack in a world-writable directory. Affected users should update the package immediately.
Azərbaycanca: CVE-2026-73585 zəifliyi sblim-cmpi-base paketində aşkarlanıb. Provayder qeydiyyat skriptlərində müvəqqəti faylların təhlükəsiz yaradılmaması, yerli imtiyazsız istifadəçiyə simvolik keçid hücumu vasitəsilə ixtiyari fayla imtiyazlı yazma əməliyyatını yönləndirməyə imkan verir. Təsirə məruz qalan sistemlərdə paketi yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-732
FAQ2
Which package is affected by CVE-2026-73585?
This vulnerability has been found in the sblim-cmpi-base package.
How can CVE-2026-73585 be exploited?
Due to insecure temporary file creation in the provider registration scripts, a local unprivileged user can redirect privileged writes to an arbitrary file via a symlink attack in a world-writable directory.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.