{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/leapp-upgrade-el9toel10/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:redhat:leapp-upgrade-el9toel10:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-75092"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["leapp-upgrade-el9toel10"],"_cs_severities":["high"],"_cs_tags":["vulnerability","privilege-escalation","linux","rhel"],"_cs_type":"advisory","_cs_vendors":["Red Hat"],"content_html":"\u003cp\u003eCVE-2026-75092 is a privilege escalation vulnerability within the scan_mysql actor of the leapp-upgrade-el9toel10 package, distributed by Red Hat. The vulnerability arises because the Leapp actor executes the 'mysqld' binary with root privileges during the RHEL 9 to RHEL 10 upgrade process, bypassing the standard MySQL systemd unit that enforces the 'mysql' service user.\u003c/p\u003e\n\u003cp\u003eAn attacker who has already compromised the 'mysql' OS user account can manipulate the MySQL persisted configuration file (mysqld-auto.cnf) to point the 'plugin_dir' to a directory they control, such as /var/lib/mysql. By configuring early plugin loading options within this file, the attacker forces the 'mysqld' process to load a malicious shared object. When an administrator subsequently executes the documented Leapp upgrade workflow, the 'mysqld' process executes the malicious code as root within an unconfined SELinux domain, granting the attacker full system control. This vulnerability highlights a critical failure in the privilege transition during the system upgrade lifecycle.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains initial access to the system with the identity of the 'mysql' service user.\u003c/li\u003e\n\u003cli\u003eAttacker creates a malicious shared object file (.so) and places it within /var/lib/mysql.\u003c/li\u003e\n\u003cli\u003eAttacker modifies the persisted configuration file /var/lib/mysql/mysqld-auto.cnf.\u003c/li\u003e\n\u003cli\u003eAttacker updates the 'plugin_dir' configuration entry in mysqld-auto.cnf to /var/lib/mysql.\u003c/li\u003e\n\u003cli\u003eAttacker adds configuration options such as 'early_plugin_load' to point to the malicious shared object.\u003c/li\u003e\n\u003cli\u003eAn administrator runs the RHEL 9 to RHEL 10 Leapp preupgrade or upgrade workflow.\u003c/li\u003e\n\u003cli\u003eThe 'scan_mysql' actor invokes 'mysqld' as root, executing the malicious shared object during the validation phase.\u003c/li\u003e\n\u003cli\u003eAttacker gains root access with a full capability set, resulting in persistent system compromise.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-75092 allows an attacker to transition from the limited 'mysql' service account to full root privileges on a RHEL system. This vulnerability impacts systems undergoing an upgrade from RHEL 9 to RHEL 10. If successful, the attacker can install backdoors, exfiltrate sensitive data, or disable security controls, effectively compromising the integrity and confidentiality of the host operating system.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for detection and mitigation teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ePatch the leapp-upgrade-el9toel10 package to the version provided by Red Hat that addresses CVE-2026-75092.\u003c/li\u003e\n\u003cli\u003eAudit existing configuration files in /var/lib/mysql/ for suspicious 'plugin_dir' or 'early_plugin_load' directives that reference non-standard paths.\u003c/li\u003e\n\u003cli\u003eMonitor process creation logs for 'mysqld' executions where the parent process is associated with the 'leapp' upgrade framework.\u003c/li\u003e\n\u003cli\u003eEnsure that the 'mysql' service user has no writable access to directories other than intended data directories to prevent the placement of malicious shared objects.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-15T09:39:23Z","date_published":"2026-09-15T09:39:23Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-75092/","summary":"A privilege escalation vulnerability (CVE-2026-75092) in the leapp-upgrade-el9toel10 package allows an attacker with mysql OS identity access to execute arbitrary code as root during RHEL upgrade workflows.","title":"Privilege Escalation in leapp-upgrade-el9toel10","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-75092/"}],"language":"en","title":"CraftedSignal Threat Feed - Leapp-Upgrade-El9toel10","version":"https://jsonfeed.org/version/1.1"}