Fedora MRTG Privilege Escalation Vulnerability Patched

Fedora MRTG Privilege Escalation Vulnerability Patched

First seen 4 Sep 2026, 08:45 UTC Linuxsecurity 45.0

Article Content

Browse articles
ThreatCluster

A symlink-following privilege escalation vulnerability (CVE-2026-72694) was identified in the Multi Router Traffic Grapher (MRTG), affecting Fedora systems. The vulnerability allows local privilege escalation via PID file path manipulation. Fedora has released patches for MRTG versions 2.17.10-13 and 2.17.10-14 to address this issue. Users are advised to apply the updates promptly to secure their systems. The vulnerability was published on August 11, 2026, and is linked to bug report #2460973. The exploit could potentially allow unauthorized users to gain elevated privileges on affected systems. The patch can be installed using the 'dnf' update program. Security professionals should ensure their systems are updated to mitigate risks associated with this vulnerability.

Key Points: • CVE-2026-72694 allows local privilege escalation in MRTG. • Patches available for affected Fedora versions 2.17.10-13 and 2.17.10-14. • Immediate action is recommended to secure systems against this vulnerability.

Ask AI about this cluster

Timeline

2026-08-11
CVE-2026-72694 published
A symlink-following privilege escalation vulnerability in MRTG was disclosed, impacting Fedora systems.
Linuxsecurity
2026-08-26
Patch released for MRTG
Fedora released updates 2.17.10-13 and 2.17.10-14 to fix CVE-2026-72694, addressing the privilege escalation issue.
Linuxsecurity
Recent
Users urged to update
Security professionals are advised to apply the patches promptly to mitigate the risk of exploitation.
Linuxsecurity