VYPR
High severity8.8NVD Advisory· Published Apr 6, 2022· Updated Jun 17, 2026

CVE-2022-26110

CVE-2022-26110

Description

An issue was discovered in HTCondor 8.8.x before 8.8.16, 9.0.x before 9.0.10, and 9.1.x before 9.6.0. When a user authenticates to an HTCondor daemon via the CLAIMTOBE method, the user can then impersonate any entity when issuing additional commands to that daemon.

Affected products

5
  • cpe:2.3:a:wisc:htcondor:*:*:*:*:*:*:*:*
    Range: >=8.8.0,<8.8.16
  • Debian/linux2 versions
    cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
    • cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
  • Condor Project/Htcondorcpe-rescue2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: <8.8.16, <9.0.10, <9.6.0

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.