PatchSiren

acl project CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH acl project CVE published 2026-06-29

CVE-2026-54369

A HIGH severity vulnerability, CVE-2026-54369, was found in acl before version 2.4.0. This vulnerability allows local attackers to escalate privileges by replacing any pathname component with a symbolic link, enabling unauthorized manipulation of access control lists. The acl package, specifically versions before 2.4.0, contains a symlink traversal vulnerability in its libacl pathname-based functions. Thi [truncated]