CVE-2026-54228
A time-of-check time-of-use (TOCTOU) race condition was found in the abrt-dbus D-Bus service's SetElement method. Between dump directory cre
CVSS
7.8
High
EPSS
0.1%
p3
KEV
—
Exploit Today
1
0-100
Published: Jun 13, 2026 · Last modified: Aug 13, 2026 · CWE-367
0.1%EPSS · 30 days0.1%
2026-08-042026-08-31
A time-of-check time-of-use (TOCTOU) race condition was found in the abrt-dbus D-Bus service's SetElement method. Between dump directory creation and post-create event execution, any local user can call SetElement to write arbitrary text files into the root-owned dump directory, bypassing package validation and allowing crashes of unpackaged binaries to survive post-create processing.
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:48819
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:48864
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:48865
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:48866
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:54272
- access.redhat.comhttps://access.redhat.com/security/cve/CVE-2026-54228
- bugzilla.redhat.comhttps://bugzilla.redhat.com/show_bug.cgi?id=2488531
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:48819
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:48864
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:48865
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:48866
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:54272
- access.redhat.comhttps://access.redhat.com/security/cve/CVE-2026-54228
- bugzilla.redhat.comhttps://bugzilla.redhat.com/show_bug.cgi?id=2488531
- security.access.redhat.comhttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54228.json
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-19118——
———A time-of-check time-of-use race condition vulnerability was identified in GitHub Enterprise Server that allowed remote code execution. Exploitation required an authenticated user with write access to a repository and precise timing of concurrent upload requests. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.22 and was fixed in versions 3.17.20, 3.18.14, 3.19.11, 3.20.7, 3.21.5, and 3.22.0. This vulnerability was reported via the GitHub Bug Bounty program.7hCVE-2026-78319——
———A service running on the affected products contains a potential Time-of-Check Time-of-Use (TOCTOU) race condition.
An unauthenticated remote attacker could exploit this race condition to bypass intended security controls.
This may result in the execution of unauthorized code.11hCVE-2026-78422——
——0Subject::new_for_owner() in the zbus_polkit crate encodes the uid entry of a unix-process polkit subject as an unsigned 32-bit integer (D-Bus type u), whereas the org.freedesktop.PolicyKit1.Authority interface specifies a signed 32-bit integer (D-Bus type i). Because of this type mismatch, polkit silently discards the caller-supplied UID and instead determines the subject's owner itself by looking up the PID in /proc, a lookup that is inherently subject to a time-of-check/time-of-use race.
Consequently, an application that passes a UID obtained from a trustworthy source — for example SO_PEERCRED Unix socket peer credentials — in order to defend against PID reuse receives no protection, and the supplied UID has no effect on the authorization decision. A local unprivileged attacker who can cause an authorized process to terminate and then win the race to have their own process assigned the same PID can be authorized under the identity of the terminated process, bypassing the polkit authorization check and performing actions the attacker is not entitled to.
This issue affects zbus_polkit before 5.1.0.8hCVE-2026-19410—9.5%
——3An Incorrect Authorization vulnerability in GitHub Trigger Comment Control in Google Cloud Build prior to 2026-06-24 on Google Cloud Platform allows a remote attacker to execute unreviewed code in the build environment using webhook suppression.
This vulnerability was patched on 24 June 2026, and no customer action is needed.1dCVE-2026-547549.6 CRI22.0%
——7Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, marketplace settlement in core/kapp/market/market.go reads MarketOrderData.ReferralPercentage from the listing while reading asset.Royalties.MarketPercentage live at purchase time. An asset owner can create a valid listing and then use AssetTrigger UpdateRoyalties to make the combined referral and royalty percentages exceed the bid. executeBuyMarket pays referral and royalty amounts unconditionally while computeMarketOwnerAmount silently skips a nonpositive seller remainder, allowing MarketBuy, BuyItNow, or auction Claim settlement to credit more KLV or sale currency than the buyer paid. This can create unbacked currency and corrupt token supply integrity. This issue is fixed in version 1.7.19.1dCVE-2026-822383.1 LOW6.8%
——2filebrowser from version 2.24.0 contains a race condition in the TUS upload handler that allows authenticated users to write past the declared Upload-Length by sending concurrent PATCH requests. Attackers can send multiple simultaneous PATCH requests at the same offset to bypass length validation, resulting in files that exceed their declared size and triggering completion hooks for oversized uploads.1d