VYPR

acl

by ACL

CVEs (2)

  • CVE-2026-54369HigJun 29, 2026
    risk 0.46cvss 7.1epss 0.00

    acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a…

  • CVE-2026-54370MedJun 29, 2026
    risk 0.41cvss 6.3epss 0.00

    acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link between an lstat() check and subsequent symlink-following operations…