{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/oetiker/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-72694"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["MRTG"],"_cs_severities":["high"],"_cs_tags":["privilege-escalation","symlink","linux"],"_cs_type":"advisory","_cs_vendors":["Oetiker"],"content_html":"\u003cp\u003eMRTG (Multi Router Traffic Grapher) contains a vulnerability (CVE-2026-72694) in its privilege-dropping mechanism when the daemon is started as root. A low-privileged local user can exploit this by manipulating the path used for the Process ID (PID) file. Because the application fails to verify the target of the PID file path before performing file operations, it can be tricked into following a symbolic link (symlink) to an arbitrary file. When the daemon drops privileges, it inadvertently changes the ownership of the pointed-to file to the daemon user, enabling unauthorized access or modification of sensitive system files. This vulnerability poses a significant risk for privilege escalation on systems where MRTG is deployed with elevated startup permissions.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows a local, non-root user to gain control over arbitrary files on the filesystem by modifying their ownership. This can lead to full compromise of sensitive configuration files, shadow passwords, or system binaries, effectively escalating privileges to that of the daemon account or higher, depending on the files targeted.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor for symlink creation in directories where MRTG writes its PID files.\u003c/li\u003e\n\u003cli\u003eAudit existing MRTG deployments to ensure the daemon is not configured to run in ways that permit user-level control over its PID directory.\u003c/li\u003e\n\u003cli\u003eRestrict the ability of low-privileged users to create symlinks in system-critical directories using fs.protected_symlinks kernel parameters.\u003c/li\u003e\n\u003cli\u003eApply patches provided by the vendor when available to address the insecure file path handling.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-11T09:51:08Z","date_published":"2026-08-11T09:51:08Z","id":"https://feed.craftedsignal.io/briefs/2026-08-mrtg-symlink-priv-esc/","summary":"A local symlink following vulnerability in the MRTG daemon allows low-privileged users to achieve local privilege escalation by manipulating PID file ownership.","title":"Local Privilege Escalation via Symlink in MRTG Daemon","url":"https://feed.craftedsignal.io/briefs/2026-08-mrtg-symlink-priv-esc/"}],"language":"en","title":"CraftedSignal Threat Feed - Oetiker","version":"https://jsonfeed.org/version/1.1"}