CVE-2026-75038
Received Received - Intake

Symbolic Link Following Local DoS in LACT

Vulnerability report for CVE-2026-75038, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-25

Last updated on: 2026-08-25

Assigner: SUSE

Description

UNIX symbolic link (symlink) following vulnerability in ilya-zlobintsev/LACT allows for local denial-of-service.Β This issue affects LACT: through 0.10.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-25
Last Modified
2026-08-25
Generated
2026-08-25
AI Q&A
2026-08-25
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ilya_zlobintsev lact to 0.10.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-61 The product, when opening a file or directory, does not sufficiently account for when the file is a symbolic link that resolves to a target outside of the intended control sphere. This could allow an attacker to cause the product to operate on unauthorized files.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a UNIX symlink following vulnerability in the LACT software up to version 0.10.0. It allows a local attacker to cause a denial-of-service by exploiting symbolic links.

Detection Guidance

To detect this vulnerability, check for symlink following issues in LACT versions through 0.10.0. Inspect system logs for unusual file access patterns or errors related to LACT components like lactd. Verify if any symlinks are being improperly followed by the application.

Impact Analysis

A local attacker could exploit this to crash or disrupt the LACT application, potentially leading to service unavailability or system instability.

Compliance Impact

This vulnerability is a local denial-of-service issue caused by symlink following in LACT through version 0.10.0. It does not directly impact data confidentiality or integrity, which are key concerns for GDPR or HIPAA compliance. However, availability disruptions from DoS could indirectly affect system operations subject to these regulations.

Mitigation Strategies

Update LACT to the latest version beyond 0.10.0 to address the symlink following vulnerability. Avoid running LACT with elevated privileges to limit potential impact.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-75038. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart