Vulnerability Description
Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In version 6.0.0, the logfile check legacy database migration moved a predictable path from /tmp with os.rename() and allowed a local user controlling the plugin account to place a symlink that would be followed by sqlite3.connect() during a root-run check.
Related Weaknesses (CWE)
References
- https://github.com/Linuxfabrik/monitoring-plugins/commit/6df1f574aa9dc6541e092f1
- https://github.com/Linuxfabrik/monitoring-plugins/security/advisories/GHSA-w2gg-
FAQ
What is CVE-2026-67433?
CVE-2026-67433 is a documented vulnerability. Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In version 6.0.0, the logfile check legacy database migration moved a predictable ...
How severe is CVE-2026-67433?
CVSS scoring is not yet available for CVE-2026-67433. Check NVD for updates.
Is there a patch for CVE-2026-67433?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.