Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-8w6w-23mq-h8rg | Linuxfabrik Monitoring Plugins: Sudoers may be able to obtain privilege escalation via /usr/bin/apt-get arguments |
Tue, 18 Aug 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Linuxfabrik
Linuxfabrik monitoring-plugins |
|
| Vendors & Products |
Linuxfabrik
Linuxfabrik monitoring-plugins |
Tue, 18 Aug 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, Nagios, and related systems. Prior to version 5.1.0, the shipped assets/sudoers/Debian.sudoers policy allowed the nagios or icinga account to execute /usr/bin/apt-get as root without restricting its arguments. An attacker who already controls that monitoring account can supply the APT::Update::Pre-Invoke option to execute an arbitrary command while apt-get runs with root privileges, resulting in a root shell and complete compromise of the host. The vulnerable rule supports the check-plugins/deb-updates/deb-updates plugin, but it authorized arbitrary apt-get argument sequences rather than only the required apt-get update --quiet 2 command. This issue is fixed in version 5.1.0. | |
| Title | Linuxfabrik Monitoring Plugins Sudoers: /usr/bin/apt-get arguments allow privilege escalation | |
| Weaknesses | CWE-88 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-18T20:53:22.189Z
Reserved: 2026-06-08T18:11:06.660Z
Link: CVE-2026-52817
No data.
Status : Received
Published: 2026-08-18T21:16:34.820
Modified: 2026-08-18T21:16:34.820
Link: CVE-2026-52817
No data.
OpenCVE Enrichment
Updated: 2026-08-18T23:00:13Z
-
CWE-88
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
Github GHSA