← العودة للجدول
CVE-2026-11837
CVE-2026-11837 — A local privilege escalation vulnerability was found in the ansible.posix author
📅 2026-06-10
🟠 High 🔥 No NVD Exploit Vulnerability CVSS 7.3

📋 الوصف الكامل

A local privilege escalation vulnerability was found in the ansible.posix authorized_key module. The module's keyfile() function uses os.chown() instead of os.lchown() and opens files without O_NOFOLLOW when managing SSH authorized keys. An unprivileged local user can pre-stage symbolic links in their ~/.ssh directory to redirect file ownership changes to arbitrary system paths when an operat

💻 الأنظمة المتأثرة

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-11837

📡 المصدر

NVD

✅ الحلول والتخفيف

Refer to CVE-2026-11837 NVD advisory

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←