6.1 CVE-2026-15779

Enriched by CISA Privilege Escalation CSRF
 

A flaw was found in samba's pam_winbind. When mkhomedir is enabled, pam_winbind chowns the target account's home directory without validating the path is not a critical system directory such as /. On affected systems, accounts with / as their home directory (a common default for system accounts) can have this triggered not only by root, but by a non-root user holding a narrow sudo delegation to run commands as that account, causing ownership of / to change and resulting in severe denial of service (SSH, sudo, and package-manager failures). The change does not grant write access to / (which ships with restrictive 0555 permissions on RHEL), so the impact is availability loss rather than further privilege escalation.
https://nvd.nist.gov/vuln/detail/CVE-2026-15779

Categories

CWE-732 : Incorrect Permission Assignment for Critical Resource
When a resource is given a permission setting that provides access to a wider range of actors than required, it could lead to the exposure of sensitive information, or the modification of that resource by unintended parties. This is especially dangerous when the resource is related to program configuration, execution, or sensitive user data. For example, consider a misconfigured storage account for the cloud that can be read or written by a public or anonymous user.

References


 

AFFECTED (from MITRE)


Vendor Product Versions
Red Hat Red Hat Enterprise Linux 10
    Red Hat Red Hat Enterprise Linux 6
      Red Hat Red Hat Enterprise Linux 7
        Red Hat Red Hat Enterprise Linux 8
          Red Hat Red Hat Enterprise Linux 9
            © 2022 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.

            CPE

            cpe start end


            REMEDIATION




            EXPLOITS


            Exploit-db.com

            id description date
            No known exploits

            POC Github

            Url
            No known exploits

            Other Nist (github, ...)

            Url
            No known exploits


            CAPEC


            Common Attack Pattern Enumerations and Classifications

            id description severity
            1 Accessing Functionality Not Properly Constrained by ACLs
            High
            122 Privilege Abuse
            Medium
            127 Directory Indexing
            Medium
            17 Using Malicious Files
            Very High
            180 Exploiting Incorrectly Configured Access Control Security Levels
            Medium
            206 Signing Malicious Code
            Very High
            234 Hijacking a privileged process
            Medium
            60 Reusing Session IDs (aka Session Replay)
            High
            61 Session Fixation
            High
            62 Cross Site Request Forgery
            Very High
            642 Replace Binaries
            High


            MITRE


            Techniques

            id description
            T1083 File and Directory Discovery
            T1134.001 Access Token Manipulation:Token Impersonation/Theft
            T1505.005 Server Software Component: Terminal Services DLL
            T1548 Abuse Elevation Control Mechanism
            T1550.004 Use Alternate Authentication Material:Web Session Cookie
            T1553.002 Subvert Trust Controls:Code Signing
            T1554 Compromise Client Software Binary
            T1574.005 Hijack Execution Flow: Executable Installer File Permissions Weakness
            T1574.010 Hijack Execution Flow: ServicesFile Permissions Weakness
            © 2022 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.

            Mitigations

            id description
            M1018 An adversary must already have administrator level access on the local system to make full use of this technique; be sure to restrict users and accounts to the least privileges they require.
            M1024 Consider using Group Policy to configure and block modifications to Terminal Services parameters in the Registry.
            M1018 Limit the privileges of cloud accounts to assume, create, or impersonate additional roles, policies, and permissions to only those required. Where just-in-time access is enabled, consider requiring manual approval for temporary elevation of privileges.
            M1054 Configure browsers or tasks to regularly delete persistent cookies.
            M1045 Ensure all application component binaries are signed by the correct application developers.
            M1018 Limit privileges of user accounts and groups so that only authorized administrators can interact with service changes and service binary target path locations. Deny execution from user directories such as file download directories and temp directories where able.
            M1018 Limit privileges of user accounts and groups so that only authorized administrators can interact with service changes and service binary target path locations. Deny execution from user directories such as file download directories and temp directories where able.
            © 2022 The MITRE Corporation. Esta obra se reproduce y distribuye con el permiso de The MITRE Corporation.