CVE-2026-26104
published 2026-02-25CVE-2026-26104: A flaw was found in the udisks storage management daemon that allows unprivileged users to back up LUKS encryption headers without authorization. The issue…
PriorityP427medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.07%
0.1th percentile
A flaw was found in the udisks storage management daemon that allows unprivileged users to back up LUKS encryption headers without authorization. The issue occurs because a privileged D-Bus method responsible for exporting encryption metadata does not perform a policy check. As a result, sensitive cryptographic metadata can be read and written to attacker-controlled locations. This weakens the confidentiality guarantees of encrypted storage volumes.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | udisks2 | < udisks2 2.11.1-1 (forky) | udisks2 2.11.1-1 (forky) |
| freedesktop | udisks | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2026-26104: A flaw was found in the udisks storage management daemon that allows unprivileged users to back up LUKS encryption headers without authorization
osv·2026-02-25·CVSS 5.5
CVE-2026-26104 [MEDIUM] CVE-2026-26104: A flaw was found in the udisks storage management daemon that allows unprivileged users to back up LUKS encryption headers without authorization
A flaw was found in the udisks storage management daemon that allows unprivileged users to back up LUKS encryption headers without authorization. The issue occurs because a privileged D-Bus method responsible for exporting encryption metadata does not perform a policy check. As a result, sensitive cryptographic metadata can be read and written to attacker-controlled locations. This weakens the confidentiality guarantees of encrypted storage volumes.
GHSA
GHSA-hjgq-ff5j-5v2m: A flaw was found in the udisks storage management daemon that allows unprivileged users to back up LUKS encryption headers without authorization
ghsa_unreviewed·2026-02-25
CVE-2026-26104 [MEDIUM] CWE-862 GHSA-hjgq-ff5j-5v2m: A flaw was found in the udisks storage management daemon that allows unprivileged users to back up LUKS encryption headers without authorization
A flaw was found in the udisks storage management daemon that allows unprivileged users to back up LUKS encryption headers without authorization. The issue occurs because a privileged D-Bus method responsible for exporting encryption metadata does not perform a policy check. As a result, sensitive cryptographic metadata can be read and written to attacker-controlled locations. This weakens the confidentiality guarantees of encrypted storage volumes.
Red Hat
udisks: Missing Authorization Check Allows Unprivileged Users to Back Up LUKS Headers via udisks D-Bus API
vendor_redhat·2026-02-25·CVSS 5.5
CVE-2026-26104 [MEDIUM] CWE-862 udisks: Missing Authorization Check Allows Unprivileged Users to Back Up LUKS Headers via udisks D-Bus API
udisks: Missing Authorization Check Allows Unprivileged Users to Back Up LUKS Headers via udisks D-Bus API
A flaw was found in the udisks storage management daemon that allows unprivileged users to back up LUKS encryption headers without authorization. The issue occurs because a privileged D-Bus method responsible for exporting encryption metadata does not perform a policy check. As a result, sensitive cryptographic metadata can be read and written to attacker-controlled locations. This weakens the confidentiality guarantees of encrypted storage volumes.
A flaw was found in the udisks storage management daemon that allows unprivileged users to back up LUKS encryption headers without authorization. The issue occurs because a privileged D-Bus method responsible for exporting encryption met
Debian
CVE-2026-26104: udisks2 - A flaw was found in the udisks storage management daemon that allows unprivilege...
vendor_debian·2026·CVSS 5.5
CVE-2026-26104 [MEDIUM] CVE-2026-26104: udisks2 - A flaw was found in the udisks storage management daemon that allows unprivilege...
A flaw was found in the udisks storage management daemon that allows unprivileged users to back up LUKS encryption headers without authorization. The issue occurs because a privileged D-Bus method responsible for exporting encryption metadata does not perform a policy check. As a result, sensitive cryptographic metadata can be read and written to attacker-controlled locations. This weakens the confidentiality guarantees of encrypted storage volumes.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 2.11.1-1)
sid: resolved (fixed in 2.11.1-1)
trixie: resolved
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-26104 udisks: Missing Authorization Check Allows Unprivileged Users to Back Up LUKS Headers via udisks D-Bus API
bugzilla·2026-01-28·CVSS 5.5
CVE-2026-26104 [MEDIUM] CVE-2026-26104 udisks: Missing Authorization Check Allows Unprivileged Users to Back Up LUKS Headers via udisks D-Bus API
CVE-2026-26104 udisks: Missing Authorization Check Allows Unprivileged Users to Back Up LUKS Headers via udisks D-Bus API
Missing authorization (polkit) vulnerability in the org.freedesktop.UDisks2.Encrypted.HeaderBackup D-Bus method of udisks. The flaw is caused by the absence of a call to udisks_daemon_util_check_authorization_sync() in the handle_header_backup() handler. An unprivileged local user can invoke this system-bus method to cause the root-owned udisks daemon to call bd_crypto_luks_header_backup() and export LUKS headers and keyslot metadata to an arbitrary file path. This allows unauthorized disclosure of sensitive cryptographic material without authentication or user interaction.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux
Wiz
CVE-2026-4111 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-4111 [HIGH] CVE-2026-4111 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-4111 :
Rocky Linux vulnerability analysis and mitigation
A flaw was identified in the RAR5 archive decompression logic of the libarchive library, specifically within the archive_read_data() processing path. When a specially crafted RAR5 archive is processed, the decompression routine may enter a state where internal logic prevents forward progress. This condition results in an infinite loop that continuously consumes CPU resources. Because the archive passes checksum validation and appears structurally valid, affected applications cannot detect the issue before processing. This can allow attackers to cause persistent denial-of-service conditions in services that automatically process archives.
Source : NVD
## 7.5
Score
Published March 13, 2026
Severity HIGH
CNA Score
Wiz
CVE-2025-14905 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2025-14905 [MEDIUM] CVE-2025-14905 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-14905 :
Rocky Linux vulnerability analysis and mitigation
schema_attr_enum_callback
schema.c
Source : NVD
## 7.2
Score
Published February 23, 2026
Severity HIGH
CNA Score 7.2
Affected Technologies
Rocky Linux
Alma Linux
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 64.4
Exploitation Probability (EPSS) 0.5
Affected packages and libraries
python3-lib389
389-ds-base-legacy-tools
Sources
NVD
AlmaLinux 8 Severity MEDIUM Has Fix Added at: Mar 29, 2026
AlmaLinux 9 Severity MEDIUM Has Fix Added at: Mar 02, 2026
Debian 11, 12, 13 Severity HIGH No Fix Added at: Feb 24, 2026
Echo Severity HIGH No Fix Added at: Feb 24, 2026
Red Hat 6, 7 Severity MEDIUM No Fix Added at: F
Wiz
CVE-2026-1299 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.0
CVE-2026-1299 [MEDIUM] CVE-2026-1299 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-1299 :
Rocky Linux vulnerability analysis and mitigation
The
email module, specifically the "BytesGenerator" class, didn’t properly quote newlines for email headers when
serializing an email message allowing for header injection when an email
is serialized. This is only applicable if using "LiteralHeader" writing headers that don't respect email folding rules, the new behavior will reject the incorrectly folded headers in "BytesGenerator".
Source : NVD
## 6
Score
Published January 23, 2026
Severity MEDIUM
CNA Score 6.0
Affected Technologies
Rocky Linux
Python Interpreter
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 13.5
Exploitation Probability (EPSS) N/A
Affected pac
Wiz
CVE-2025-12801 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2025-12801 [MEDIUM] CVE-2025-12801 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-12801 :
Rocky Linux vulnerability analysis and mitigation
A vulnerability was recently discovered in the rpc.mountd daemon in the nfs-utils package for Linux, that allows a NFSv3 client to escalate the
privileges assigned to it in the /etc/exports file at mount time. In particular, it allows the client to access any subdirectory or subtree of an exported directory, regardless of the set file permissions, and regardless of any 'root_squash' or 'all_squash' attributes that would normally be expected to apply to that client.
Source : NVD
## 6.5
Score
Published March 4, 2026
Severity MEDIUM
CNA Score 6.5
Affected Technologies
Rocky Linux
Alma Linux
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probabilit
Wiz
CVE-2025-15366 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.9
CVE-2025-15366 [MEDIUM] CVE-2025-15366 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-15366 :
Rocky Linux vulnerability analysis and mitigation
The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.
Source : NVD
## 5.9
Score
Published January 20, 2026
Severity MEDIUM
CNA Score 5.9
Affected Technologies
Rocky Linux
Python Interpreter
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 23.8
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
python311-testsuite
python36:3.6::python-pymongo
Sources
AlmaLinux 8 Severity MEDIUM Has Fix Added at: Feb 08, 2026
AlmaLinux 9 Severity MEDIUM Has Fix Added at: Mar 12, 2026
Chainguard
Wiz
CVE-2026-1761 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.6
CVE-2026-1761 [HIGH] CVE-2026-1761 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-1761 :
Rocky Linux vulnerability analysis and mitigation
A flaw was found in libsoup. This stack-based buffer overflow vulnerability occurs during the parsing of multipart HTTP responses due to an incorrect length calculation. A remote attacker can exploit this by sending a specially crafted multipart HTTP response, which can lead to memory corruption. This issue may result in application crashes or arbitrary code execution in applications that process untrusted server responses, and it does not require authentication or user interaction.
Source : NVD
## 8.6
Score
Published February 2, 2026
Severity HIGH
CNA Score 8.6
Affected Technologies
Rocky Linux
Alma Linux
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Explo
Wiz
CVE-2026-0719 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.6
CVE-2026-0719 [HIGH] CVE-2026-0719 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0719 :
Rocky Linux vulnerability analysis and mitigation
A flaw was identified in the NTLM authentication handling of the libsoup HTTP library, used by GNOME and other applications for network communication. When processing extremely long passwords, an internal size calculation can overflow due to improper use of signed integers. This results in incorrect memory allocation on the stack, followed by unsafe memory copying. As a result, applications using libsoup may crash unexpectedly, creating a denial-of-service risk.
Source : NVD
## 8.6
Score
Published January 8, 2026
Severity HIGH
CNA Score 8.6
Affected Technologies
Rocky Linux
Alma Linux
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Pe
Wiz
CVE-2026-0865 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.9
CVE-2026-0865 [MEDIUM] CVE-2026-0865 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-0865 :
Rocky Linux vulnerability analysis and mitigation
User-controlled header names and values containing newlines can allow injecting HTTP headers.
Source : NVD
## 5.9
Score
Published January 20, 2026
Severity MEDIUM
CNA Score 5.9
Affected Technologies
Rocky Linux
Python Interpreter
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 32.7
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
python3.15-freethreading-libs
python313-nogil
Sources
NVD
AlmaLinux 8 Severity MEDIUM Has Fix Added at: Feb 08, 2026
AlmaLinux 9 Severity MEDIUM Has Fix Added at: Mar 13, 2026
CBL-Mariner 2.0 Severity MEDIUM Has Fix Added at: Mar 10, 2026
CBL-Mariner 3.0 Severity
Wiz
CVE-2025-15367 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.9
CVE-2025-15367 [MEDIUM] CVE-2025-15367 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-15367 :
Rocky Linux vulnerability analysis and mitigation
The poplib module, when passed a user-controlled command, can have
additional commands injected using newlines. Mitigation rejects commands
containing control characters.
Source : NVD
## 5.9
Score
Published January 20, 2026
Severity MEDIUM
CNA Score 5.9
Affected Technologies
Rocky Linux
Python Interpreter
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 23.8
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
python310-tk
python312-tk
Sources
AlmaLinux 8 Severity MEDIUM Has Fix Added at: Feb 08, 2026
AlmaLinux 9 Severity MEDIUM Has Fix Added at: Mar 12, 2026
Chainguard Has Fix Added at: Jan 28
Wiz
CVE-2025-14523 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.2
CVE-2025-14523 [HIGH] CVE-2025-14523 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-14523 :
Rocky Linux vulnerability analysis and mitigation
A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor the first Host: header, so this mismatch can cause vhost confusion where a proxy routes a request to one backend but the backend interprets it as destined for another host. This discrepancy enables request-smuggling style attacks, cache poisoning, or bypassing host-based access controls when an attacker supplies duplicate Host headers.
Source : NVD
## 8.2
Score
Published December 11, 2025
Severity HIGH
CNA Score 8.2
Affected Technologies
Rocky Linux
Alma Linux
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
Wiz
CVE-2026-26104 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.5
CVE-2026-26104 [MEDIUM] CVE-2026-26104 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-26104 :
NixOS vulnerability analysis and mitigation
A flaw was found in the udisks storage management daemon that allows unprivileged users to back up LUKS encryption headers without authorization. The issue occurs because a privileged D-Bus method responsible for exporting encryption metadata does not perform a policy check. As a result, sensitive cryptographic metadata can be read and written to attacker-controlled locations. This weakens the confidentiality guarantees of encrypted storage volumes.
Source : NVD
## 5.5
Score
Published February 25, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
NixOS
Rocky Linux
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 1
2026-02-25
Published