CVE-2026-54576
— UNSCOREDpublic exploit availablePublished 2026-09-17 · Updated 2026-09-18
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
mport is the MidnightBSD Package Manager. Prior to 2.7.8, do_actual_install() in libmport/bundle_read_install_pkg.c used path-based lstat(), chown(), stat(), and chmod() operations while installing package files. A local attacker with write access to a target directory could replace a checked file with a symlink before privileged ownership or mode changes were applied, redirecting those changes to an attacker-selected path and compromising filesystem integrity or permissions. This issue is fixed in version 2.7.8.
Weaknesses
CWE-59, CWE-367
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- UNSCOREDCVE-2026-54587PoC
- MEDIUMCVE-2026-86861PoC
- HIGHCVE-2026-100419PoC
- HIGHCVE-2026-100597PoC
- HIGHCVE-2026-100690PoC
- HIGHCVE-2026-100692PoC
- HIGHCVE-2026-100713PoC
- CRITICALCVE-2026-100715PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.