CVE-2026-26103
published 2026-02-25CVE-2026-26103: A flaw was found in the udisks storage management daemon that exposes a privileged D-Bus API for restoring LUKS encryption headers without proper authorization…
PriorityP431high7.1CVSS 3.1
AVLACLPRLUINSUCNIHAH
EPSS
0.07%
0.1th percentile
A flaw was found in the udisks storage management daemon that exposes a privileged D-Bus API for restoring LUKS encryption headers without proper authorization checks. The issue allows a local unprivileged user to instruct the root-owned udisks daemon to overwrite encryption metadata on block devices. This can permanently invalidate encryption keys and render encrypted volumes inaccessible. Successful exploitation results in a denial-of-service condition through irreversible data loss.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | udisks2 | < udisks2 2.11.1-1 (forky) | udisks2 2.11.1-1 (forky) |
| freedesktop | udisks | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
osv7.1HIGH
vendor_debian7.1LOW
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2026-26103: A flaw was found in the udisks storage management daemon that exposes a privileged D-Bus API for restoring LUKS encryption headers without proper auth
osv·2026-02-25·CVSS 7.1
CVE-2026-26103 [HIGH] CVE-2026-26103: A flaw was found in the udisks storage management daemon that exposes a privileged D-Bus API for restoring LUKS encryption headers without proper auth
A flaw was found in the udisks storage management daemon that exposes a privileged D-Bus API for restoring LUKS encryption headers without proper authorization checks. The issue allows a local unprivileged user to instruct the root-owned udisks daemon to overwrite encryption metadata on block devices. This can permanently invalidate encryption keys and render encrypted volumes inaccessible. Successful exploitation results in a denial-of-service condition through irreversible data loss.
GHSA
GHSA-fw7p-cggr-9xm6: A flaw was found in the udisks storage management daemon that exposes a privileged D-Bus API for restoring LUKS encryption headers without proper auth
ghsa_unreviewed·2026-02-25
CVE-2026-26103 [HIGH] CWE-862 GHSA-fw7p-cggr-9xm6: A flaw was found in the udisks storage management daemon that exposes a privileged D-Bus API for restoring LUKS encryption headers without proper auth
A flaw was found in the udisks storage management daemon that exposes a privileged D-Bus API for restoring LUKS encryption headers without proper authorization checks. The issue allows a local unprivileged user to instruct the root-owned udisks daemon to overwrite encryption metadata on block devices. This can permanently invalidate encryption keys and render encrypted volumes inaccessible. Successful exploitation results in a denial-of-service condition through irreversible data loss.
Red Hat
udisks: Missing Authorization Check Allows Unprivileged Users to Restore LUKS Headers via udisks D-Bus API
vendor_redhat·2026-02-25·CVSS 7.1
CVE-2026-26103 [HIGH] CWE-862 udisks: Missing Authorization Check Allows Unprivileged Users to Restore LUKS Headers via udisks D-Bus API
udisks: Missing Authorization Check Allows Unprivileged Users to Restore LUKS Headers via udisks D-Bus API
A flaw was found in the udisks storage management daemon that exposes a privileged D-Bus API for restoring LUKS encryption headers without proper authorization checks. The issue allows a local unprivileged user to instruct the root-owned udisks daemon to overwrite encryption metadata on block devices. This can permanently invalidate encryption keys and render encrypted volumes inaccessible. Successful exploitation results in a denial-of-service condition through irreversible data loss.
A flaw was found in the udisks storage management daemon that exposes a privileged D-Bus API for restoring LUKS encryption headers without proper authorization checks. The issue allows a local unprivi
Debian
CVE-2026-26103: udisks2 - A flaw was found in the udisks storage management daemon that exposes a privileg...
vendor_debian·2026·CVSS 7.1
CVE-2026-26103 [HIGH] CVE-2026-26103: udisks2 - A flaw was found in the udisks storage management daemon that exposes a privileg...
A flaw was found in the udisks storage management daemon that exposes a privileged D-Bus API for restoring LUKS encryption headers without proper authorization checks. The issue allows a local unprivileged user to instruct the root-owned udisks daemon to overwrite encryption metadata on block devices. This can permanently invalidate encryption keys and render encrypted volumes inaccessible. Successful exploitation results in a denial-of-service condition through irreversible data loss.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 2.11.1-1)
sid: resolved (fixed in 2.11.1-1)
trixie: resolved
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-26103 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.1
CVE-2026-26103 [HIGH] CVE-2026-26103 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-26103 :
NixOS vulnerability analysis and mitigation
A flaw was found in the udisks storage management daemon that exposes a privileged D-Bus API for restoring LUKS encryption headers without proper authorization checks. The issue allows a local unprivileged user to instruct the root-owned udisks daemon to overwrite encryption metadata on block devices. This can permanently invalidate encryption keys and render encrypted volumes inaccessible. Successful exploitation results in a denial-of-service condition through irreversible data loss.
Source : NVD
## 7.1
Score
Published February 25, 2026
Severity HIGH
CNA Score 7.1
Affected Technologies
NixOS
Rocky Linux
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitatio
Bugzilla
CVE-2026-26103 udisks: Missing Authorization Check Allows Unprivileged Users to Restore LUKS Headers via udisks D-Bus API
bugzilla·2026-01-28·CVSS 7.1
CVE-2026-26103 [HIGH] CVE-2026-26103 udisks: Missing Authorization Check Allows Unprivileged Users to Restore LUKS Headers via udisks D-Bus API
CVE-2026-26103 udisks: Missing Authorization Check Allows Unprivileged Users to Restore LUKS Headers via udisks D-Bus API
Missing authorization (polkit) vulnerability in the org.freedesktop.UDisks2.Block.RestoreEncryptedHeader D-Bus method of udisks. The flaw is caused by the absence of a call to udisks_daemon_util_check_authorization_sync() in the handle_restore_encrypted_header() handler. As a result, any local unprivileged user can invoke this system-bus method and cause the root-privileged udisks daemon to call bd_crypto_luks_header_restore() on an arbitrary block device. This enables destructive overwriting of LUKS headers and keyslots without authentication or user interaction, leading to permanent loss of access to encrypted data and a denial-of-service condition.
Discussion:
Thi
https://access.redhat.com/errata/RHSA-2026:3476https://access.redhat.com/errata/RHSA-2026:5831https://access.redhat.com/security/cve/CVE-2026-26103https://bugzilla.redhat.com/show_bug.cgi?id=2433719https://github.com/storaged-project/udisks/security/advisories/GHSA-c75h-phf8-ccjmhttps://access.redhat.com/errata/RHSA-2026:3476https://access.redhat.com/errata/RHSA-2026:5831https://access.redhat.com/security/cve/CVE-2026-26103https://bugzilla.redhat.com/show_bug.cgi?id=2433719https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-26103.json
2026-02-25
Published