Ad

CVE-2026-26104

MEDIUM CVSS 3.1: 5.5 EPSS 0.01%
Updated Mar 13, 2026
Freedesktop
Parameter Value
CVSS 5.5 (MEDIUM)
Type CWE-862 (Missing Authorization)
Vendor Freedesktop
Public PoC No

A flaw was found in the udisks storage management daemon that allows unprivileged users to back up LUKS encryption headers without authorization. The issue occurs because a privileged D-Bus method responsible for exporting encryption metadata does not perform a policy check. As a result, sensitive cryptographic metadata can be read and written to attacker-controlled locations.

This weakens the confidentiality guarantees of encrypted storage volumes.

Attack Parameters

Attack Vector
Local
Requires local access
Attack Complexity
Low
Easy to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v3.1

Vulnerable Products 2

Configuration From (including) Up to (excluding)
Redhat Enterprise_Linux
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
Freedesktop Udisks
cpe:2.3:a:freedesktop:udisks:2.0.0:*:*:*:*:*:*:*

Related Vulnerabilities