VYPR

leapp-upgrade-el9toel10

by Red Hat

CVEs (1)

  • CVE-2026-75092HigSep 15, 2026
    risk 0.40cvss 7.3epss

    A privilege escalation flaw was found in the scan_mysql actor of leapp-upgrade-el9toel10 (provided by leapp-repository). During RHEL 9 to RHEL 10 upgrades, the actor runs: mysqld --validate-config --log-error-verbosity=2 directly as root in the Leapp actor context, bypassing the…