Vulnerability
CVE-2026-100310
Descriptive record received from OpenCTI and minimised for consultation in the Intel portal.
- Sharing
- PUBLIC-OSINT
- Confidence
- 100
- Source
- The CVE Program
- Updated
- 26/09/2026 02:35
Description
GNU libextractor before 1.16 loads plugins from an untrusted search path specified by the LIBEXTRACTOR_PREFIX environment variable without proper privilege checks. A local attacker can exploit this by setting LIBEXTRACTOR_PREFIX to a directory containing a malicious plugin that executes arbitrary code with elevated privileges when loaded by a setuid or setgid program.
Aliases and classifications
CWE-426Untrusted Search Path
Minimised technical details
No raw data- cisa kev
- False
- cvss score
- 7
- cvss vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- cvss severity
- HIGH
Provenance
Public references
- product
https://www.gnu.org/software/libextractor/ - patch
https://git.gnunet.org/gnunet/libextractor/commit/6edfa653c048800e24a17f7e8cc2bb42659b8d01.html - VulnCheck Advisory: GNU libextractor before 1.16 Privilege Escalation via LIBEXTRACTOR_PREFIX
https://www.vulncheck.com/advisories/gnu-libextractor-before-1.16-privilege-escalation-via-libextractor-prefix - exploit
https://github.com/Haitam-lazaar/libextractor-privesc - release-notes
https://ftp.gnu.org/gnu/libextractor/
EudorIA correlation
Intel catalogue
The vulnerability is also available in the EudorIA editorial catalogue.
Open EudorIA analysisPresence in OpenCTI describes an intelligence correlation and does not, by itself, constitute evidence of compromise, legal attribution or operational guidance applicable without context verification.