CVE-2026-5107
published 2026-03-30CVE-2026-5107: A vulnerability has been found in FRRouting FRR up to 10.5.1. This affects the function process_type2_route of the file bgpd/bgp_evpn.c of the component EVPN…
PriorityP422medium4.2CVSS 3.1
AVNACHPRLUINSUCNILAL
EPSS
0.28%
20.1th percentile
A vulnerability has been found in FRRouting FRR up to 10.5.1. This affects the function process_type2_route of the file bgpd/bgp_evpn.c of the component EVPN Type-2 Route Handler. The manipulation leads to improper access controls. The attack can be initiated remotely. The attack is considered to have high complexity. The exploitability is reported as difficult. The identifier of the patch is 7676cad65114aa23adde583d91d9d29e2debd045. To fix this issue, it is recommended to deploy a patch.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | frr | < frr 10.6.0-2 (forky) | frr 10.6.0-2 (forky) |
| frrouting | frr | — | — |
| frrouting | frr | — | — |
| frrouting | frr | >= 0 < 10.6.0-2 | 10.6.0-2 |
| frrouting | frrouting | — | — |
| frrouting | frrouting | — | — |
CVSS provenance
nvdv3.14.2MEDIUMCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L
nvdv4.02.3LOWCVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.03.6LOWAV:N/AC:H/Au:S/C:N/I:P/A:P
osv2.3LOW
vendor_debian2.3LOW
vendor_redhat2.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-27p7-fq6v-hh4m: A vulnerability has been found in FRRouting FRR up to 10
ghsa_unreviewed·2026-03-30
CVE-2026-5107 [LOW] CWE-266 GHSA-27p7-fq6v-hh4m: A vulnerability has been found in FRRouting FRR up to 10
A vulnerability has been found in FRRouting FRR up to 10.5.1. This affects the function process_type2_route of the file bgpd/bgp_evpn.c of the component EVPN Type-2 Route Handler. The manipulation leads to improper access controls. The attack can be initiated remotely. The attack is considered to have high complexity. The exploitability is reported as difficult. The identifier of the patch is 7676cad65114aa23adde583d91d9d29e2debd045. To fix this issue, it is recommended to deploy a patch.
OSV
CVE-2026-5107: A vulnerability has been found in FRRouting FRR up to 10
osv·2026-03-30·CVSS 2.3
CVE-2026-5107 [LOW] CVE-2026-5107: A vulnerability has been found in FRRouting FRR up to 10
A vulnerability has been found in FRRouting FRR up to 10.5.1. This affects the function process_type2_route of the file bgpd/bgp_evpn.c of the component EVPN Type-2 Route Handler. The manipulation leads to improper access controls. The attack can be initiated remotely. The attack is considered to have high complexity. The exploitability is reported as difficult. The identifier of the patch is 7676cad65114aa23adde583d91d9d29e2debd045. To fix this issue, it is recommended to deploy a patch.
Ubuntu
FRR vulnerability
vendor_ubuntu·2026-04-15
CVE-2026-5107 FRR vulnerability
Title: FRR vulnerability
Summary: FRR could allow unintended access to network services.
It was discovered that FRR did not correctly handle certain network
requests. A remote attacker could possibly use this issue to gain
unauthorized access to resources.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
FRRouting FRR: frr: FRRouting FRR: Improper access controls in EVPN Type-2 Route Handler
vendor_redhat·2026-03-30·CVSS 2.3
CVE-2026-5107 [LOW] CWE-807 FRRouting FRR: frr: FRRouting FRR: Improper access controls in EVPN Type-2 Route Handler
FRRouting FRR: frr: FRRouting FRR: Improper access controls in EVPN Type-2 Route Handler
A vulnerability has been found in FRRouting FRR up to 10.5.1. This affects the function process_type2_route of the file bgpd/bgp_evpn.c of the component EVPN Type-2 Route Handler. The manipulation leads to improper access controls. The attack can be initiated remotely. The attack is considered to have high complexity. The exploitability is reported as difficult. The identifier of the patch is 7676cad65114aa23adde583d91d9d29e2debd045. To fix this issue, it is recommended to deploy a patch.
A flaw was found in frr package. This vulnerability, located in the EVPN Type-2 Route Handler function, allowing a remote attacker to manipulate access controls when successfully exploited. Due to the high complexit
Debian
CVE-2026-5107: frr - A vulnerability has been found in FRRouting FRR up to 10.5.1. This affects the f...
vendor_debian·2026·CVSS 2.3
CVE-2026-5107 [LOW] CVE-2026-5107: frr - A vulnerability has been found in FRRouting FRR up to 10.5.1. This affects the f...
A vulnerability has been found in FRRouting FRR up to 10.5.1. This affects the function process_type2_route of the file bgpd/bgp_evpn.c of the component EVPN Type-2 Route Handler. The manipulation leads to improper access controls. The attack can be initiated remotely. The attack is considered to have high complexity. The exploitability is reported as difficult. The identifier of the patch is 7676cad65114aa23adde583d91d9d29e2debd045. To fix this issue, it is recommended to deploy a patch.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 10.6.0-2)
sid: resolved (fixed in 10.6.0-2)
trixie: open
Citrix
Citrix Security Bulletin CTX116228
vendor_citrix·CVSS 1.9
CVE-2008-5107 [LOW] Citrix Security Bulletin CTX116228
Citrix Security Bulletin CTX116228
CVE References: CVE-2008-5107, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-5107 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-5107 [MEDIUM] CVE-2026-5107 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-5107 :
Linux Debian vulnerability analysis and mitigation
A vulnerability has been found in FRRouting FRR up to 10.5.1. This affects the function process_type2_route of the file bgpd/bgp_evpn.c of the component EVPN Type-2 Route Handler. The manipulation leads to improper access controls. The attack can be initiated remotely. The attack is considered to have high complexity. The exploitability is reported as difficult. The identifier of the patch is 7676cad65114aa23adde583d91d9d29e2debd045. To fix this issue, it is recommended to deploy a patch.
Source : NVD
## 2.3
Score
Published March 30, 2026
Severity LOW
CNA Score 2.3
Affected Technologies
Linux Debian
Linux Red Hat
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/
Bugzilla
CVE-2026-5107 frr: FRRouting FRR: Improper access controls in EVPN Type-2 Route Handler [fedora-42]
bugzilla·2026-03-30·CVSS 2.3
CVE-2026-5107 [LOW] CVE-2026-5107 frr: FRRouting FRR: Improper access controls in EVPN Type-2 Route Handler [fedora-42]
CVE-2026-5107 frr: FRRouting FRR: Improper access controls in EVPN Type-2 Route Handler [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
'version' of '42'.
Package Maintainer: If you wish for this bug to remain open because you
plan to fix it in a currently maintained versio
Bugzilla
CVE-2026-5107 FRRouting FRR: frr: FRRouting FRR: Improper access controls in EVPN Type-2 Route Handler
bugzilla·2026-03-30·CVSS 4.2
CVE-2026-5107 [MEDIUM] CVE-2026-5107 FRRouting FRR: frr: FRRouting FRR: Improper access controls in EVPN Type-2 Route Handler
CVE-2026-5107 FRRouting FRR: frr: FRRouting FRR: Improper access controls in EVPN Type-2 Route Handler
A vulnerability has been found in FRRouting FRR up to 10.5.1. This affects the function process_type2_route of the file bgpd/bgp_evpn.c of the component EVPN Type-2 Route Handler. The manipulation leads to improper access controls. The attack can be initiated remotely. The attack is considered to have high complexity. The exploitability is reported as difficult. The identifier of the patch is 7676cad65114aa23adde583d91d9d29e2debd045. To fix this issue, it is recommended to deploy a patch.
2026-03-30
Published