CVE-2026-34354

7.4

Akamai · Guardicore Platform Agent and Zero Trust Client

Akamai Guardicore Platform Agent and Zero Trust Client on Linux and macOS suffer from a TOCTOU local privilege escalation vulnerability.

Executive summary

An unprivileged local user can exploit a time-of-check time-of-use race condition in Akamai Guardicore Platform Agent and Zero Trust Client to achieve root-level privilege escalation.

Vulnerability

The GPA service creates an IPC socket in the world-writable /tmp directory and accepts unauthenticated IPC control messages, leading to a Time-of-Check Time-of-Use (CWE-367) race condition in the HandleSaveLogs function. The attacker can trigger this as an unprivileged local user.

Business impact

A successful exploit allows an unprivileged local user to make arbitrary root-owned files world-writable and leverage command injection vectors, resulting in complete system compromise and loss of confidentiality, integrity, and availability. This justifies the high CVSS score of 7.4, as local attackers can easily escalate to highest-level administrative privileges on affected Linux and macOS endpoints.

Remediation

Immediate Action: Update the Akamai Guardicore Platform Agent and Zero Trust Client to the latest patched versions provided by the vendor.

Proactive Monitoring: Monitor endpoint systems for anomalous local process executions, unauthorized file permission modifications on critical root-owned binaries, and suspicious symbolic link creations in temporary directories.

Compensating Controls: Restrict local shell access and tightly control user permissions on shared or multi-user Linux and macOS systems where agents are deployed.

Exploitation status

Public Exploit Available: No - no confirmed public exploit in the available data.

Analyst recommendation

Administrators must prioritize updating vulnerable Akamai Guardicore Platform Agent and Zero Trust Client installations immediately to eliminate the privilege escalation vector. Review local user access permissions and monitor endpoint systems closely until patches are fully deployed across the environment.

More Akamai CVEs

Sources