CVE-2026-23893
published 2026-01-22CVE-2026-23893: openCryptoki is a PKCS#11 library and provides tooling for Linux and AIX. Versions 2.3.2 and above are vulnerable to symlink-following when running in…
PriorityP336medium6.8CVSS 3.1
AVLACLPRLUIRSUCHIHAL
EPSS
0.16%
5.7th percentile
openCryptoki is a PKCS#11 library and provides tooling for Linux and AIX. Versions 2.3.2 and above are vulnerable to symlink-following when running in privileged contexts. A token-group user can redirect file operations to arbitrary filesystem targets by planting symlinks in group-writable token directories, resulting in privilege escalation or data exposure. Token and lock directories are 0770 (group-writable for token users), so any token-group member can plant files and symlinks inside them. When run as root, the base code handling token directory file access, as well as several openCryptoki tools used for administrative purposes, may reset ownership or permissions on existing files inside the token directories. An attacker with token-group membership can exploit the system when an administrator runs a PKCS#11 application or administrative tool that performs chown on files inside the token directory during normal maintenance. This issue is fixed in commit 5e6e4b4, but has not been included in a released version at the time of publication.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | opencryptoki | — | — |
| opencryptoki | opencryptoki | — | — |
| opencryptoki_project | opencryptoki | >= 2.3.2 | — |
CVSS provenance
nvdv3.16.8MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2026-23893: openCryptoki is a PKCS#11 library and provides tooling for Linux and AIX
osv·2026-01-22·CVSS 6.8
CVE-2026-23893 [MEDIUM] CVE-2026-23893: openCryptoki is a PKCS#11 library and provides tooling for Linux and AIX
openCryptoki is a PKCS#11 library and provides tooling for Linux and AIX. Versions 2.3.2 and above are vulnerable to symlink-following when running in privileged contexts. A token-group user can redirect file operations to arbitrary filesystem targets by planting symlinks in group-writable token directories, resulting in privilege escalation or data exposure. Token and lock directories are 0770 (group-writable for token users), so any token-group member can plant files and symlinks inside them. When run as root, the base code handling token directory file access, as well as several openCryptoki tools used for administrative purposes, may reset ownership or permissions on existing files inside the token directories. An attacker with token-group membership can exploit the system when an admi
Red Hat
openCryptoki: openCryptoki: Privilege Escalation or Data Exposure via Symlink Following
vendor_redhat·2026-01-22·CVSS 6.8
CVE-2026-23893 [MEDIUM] CWE-59 openCryptoki: openCryptoki: Privilege Escalation or Data Exposure via Symlink Following
openCryptoki: openCryptoki: Privilege Escalation or Data Exposure via Symlink Following
openCryptoki is a PKCS#11 library and provides tooling for Linux and AIX. Versions 2.3.2 and above are vulnerable to symlink-following when running in privileged contexts. A token-group user can redirect file operations to arbitrary filesystem targets by planting symlinks in group-writable token directories, resulting in privilege escalation or data exposure. Token and lock directories are 0770 (group-writable for token users), so any token-group member can plant files and symlinks inside them. When run as root, the base code handling token directory file access, as well as several openCryptoki tools used for administrative purposes, may reset ownership or permissions on existing files inside the token
Debian
CVE-2026-23893: opencryptoki - openCryptoki is a PKCS#11 library and provides tooling for Linux and AIX. Versio...
vendor_debian·2026·CVSS 6.8
CVE-2026-23893 [MEDIUM] CVE-2026-23893: opencryptoki - openCryptoki is a PKCS#11 library and provides tooling for Linux and AIX. Versio...
openCryptoki is a PKCS#11 library and provides tooling for Linux and AIX. Versions 2.3.2 and above are vulnerable to symlink-following when running in privileged contexts. A token-group user can redirect file operations to arbitrary filesystem targets by planting symlinks in group-writable token directories, resulting in privilege escalation or data exposure. Token and lock directories are 0770 (group-writable for token users), so any token-group member can plant files and symlinks inside them. When run as root, the base code handling token directory file access, as well as several openCryptoki tools used for administrative purposes, may reset ownership or permissions on existing files inside the token directories. An attacker with token-group membership can exploit the system when an admi
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-23893 opencryptoki: openCryptoki: Privilege Escalation or Data Exposure via Symlink Following [fedora-42]
bugzilla·2026-01-22·CVSS 6.8
CVE-2026-23893 [MEDIUM] CVE-2026-23893 opencryptoki: openCryptoki: Privilege Escalation or Data Exposure via Symlink Following [fedora-42]
CVE-2026-23893 opencryptoki: openCryptoki: Privilege Escalation or Data Exposure via Symlink Following [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-2026-13e696d26f (opencryptoki-3.26.0-3.fc42) has been submitted as an update to Fedora 42.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-13e696d26f
---
FEDORA-2026-6c3b6ec624 (opencryptoki-3.26.0-3.fc43) has been submitted as an update to Fedora 43.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-6c3b6ec624
---
FEDORA-2026-1273c7855d (opencryptoki-3.26.0-3.fc44) has been submitted as an update to Fedora 44.
https://bodhi.
Bugzilla
CVE-2026-23893 openCryptoki: openCryptoki: Privilege Escalation or Data Exposure via Symlink Following
bugzilla·2026-01-22·CVSS 6.8
CVE-2026-23893 [MEDIUM] CVE-2026-23893 openCryptoki: openCryptoki: Privilege Escalation or Data Exposure via Symlink Following
CVE-2026-23893 openCryptoki: openCryptoki: Privilege Escalation or Data Exposure via Symlink Following
openCryptoki is a PKCS#11 library and provides tooling for Linux and AIX. Versions 2.3.2 and above are vulnerable to symlink-following when running in privileged contexts. A token-group user can redirect file operations to arbitrary filesystem targets by planting symlinks in group-writable token directories, resulting in privilege escalation or data exposure. Token and lock directories are 0770 (group-writable for token users), so any token-group member can plant files and symlinks inside them. When run as root, the base code handling token directory file access, as well as several openCryptoki tools used for administrative purposes, may reset ownership or permissions on existing files i
Bugzilla
CVE-2026-23893 opencryptoki: openCryptoki: Privilege Escalation or Data Exposure via Symlink Following [fedora-43]
bugzilla·2026-01-22·CVSS 6.8
CVE-2026-23893 [MEDIUM] CVE-2026-23893 opencryptoki: openCryptoki: Privilege Escalation or Data Exposure via Symlink Following [fedora-43]
CVE-2026-23893 opencryptoki: openCryptoki: Privilege Escalation or Data Exposure via Symlink Following [fedora-43]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-2026-d63e3968e8 (opencryptoki-3.26.0-3.fc45) has been submitted as an update to Fedora 45.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-d63e3968e8
---
FEDORA-2026-13e696d26f (opencryptoki-3.26.0-3.fc42) has been submitted as an update to Fedora 42.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-13e696d26f
---
FEDORA-2026-6c3b6ec624 (opencryptoki-3.26.0-3.fc43) has been submitted as an update to Fedora 43.
https://bodhi.
Wiz
CVE-2026-23893 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.8
CVE-2026-23893 [MEDIUM] CVE-2026-23893 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-23893 :
NixOS vulnerability analysis and mitigation
openCryptoki is a PKCS#11 library and provides tooling for Linux and AIX. Versions 2.3.2 and above are vulnerable to symlink-following when running in privileged contexts. A token-group user can redirect file operations to arbitrary filesystem targets by planting symlinks in group-writable token directories, resulting in privilege escalation or data exposure. Token and lock directories are 0770 (group-writable for token users), so any token-group member can plant files and symlinks inside them. When run as root, the base code handling token directory file access, as well as several openCryptoki tools used for administrative purposes, may reset ownership or permissions on existing files inside the token directories. An attack
2026-01-22
Published