CISA_KEV · AUGUST 2026 · EARLY WARNING

Red Hat ABRT Privilege Escalation Vulnerability: Early Warning

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
HIGH
Affected component
abrt (other)
Patched version
Not yet available
CVE-2015-5287

An early warning has been issued for a privilege escalation vulnerability in the Red Hat Automatic Bug Reporting Tool (ABRT). Local users with certain permissions may be able to gain elevated privileges.

What happened

The Red Hat Automatic Bug Reporting Tool (ABRT) reportedly contains a privilege escalation vulnerability that could allow local users with certain permissions to gain elevated privileges via a symlink attack on a file with a predictable name. This vulnerability, tracked as CVE-2015-5287, is under investigation and has been flagged as exploited in the wild. To assess your exposure, review your use of ABRT and identify any local users with permissions that could be leveraged in a symlink attack.

The vulnerability was first flagged on 2026-08-26T00:00:00+00:00 and is listed in the CISA Known Exploited Vulnerabilities Catalog. The severity of this threat is high, and it is recommended to discontinue use of ABRT and transition to a supported version.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If abrt is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

You may be affected if you are using the Red Hat Automatic Bug Reporting Tool (ABRT) and have local users with certain permissions.

What should I do right now?

Discontinue use of ABRT and transition to a supported version if available. Monitor primary sources for updates.

Has this been exploited in the wild?

Yes, this vulnerability is reportedly being exploited in the wild.

Sources

Join the 0Day waitlist →

← Back to all threats