CVE-2026-72693
7.8Red Hat · Enterprise Linux
The openvt utility in Red Hat Enterprise Linux contains an improper access control vulnerability when using the -u flag, potentially allowing unauthorized privilege escalation.
Executive summary
A high-severity privilege escalation vulnerability exists in the openvt utility across multiple Red Hat Enterprise Linux versions that could allow a local attacker to gain unauthorized access.
Vulnerability
This vulnerability involves improper access control within the openvt command, which is intended to execute login as a specific user from a privileged context. An attacker with local access and low privileges can exploit this flaw to execute commands with elevated permissions (PR:L).
Business impact
Successful exploitation of this flaw allows a local user to escalate privileges to the level of the target user, which often includes root or administrative access. Given the CVSS score of 7.8, this poses a significant risk to system integrity and confidentiality, potentially leading to a full system compromise.
Remediation
Immediate Action: Monitor the Red Hat Security Advisory portal for the release of patched packages for your specific distribution and apply them immediately upon availability.
Proactive Monitoring: Review system authentication and command execution logs for anomalous activity related to the openvt utility or unexpected privilege transitions.
Compensating Controls: Restrict execution permissions for the openvt binary to only necessary administrative users to minimize the attack surface until a patch is applied.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability represents a serious risk to local system security, particularly in multi-user environments. Organizations should prioritize patching as soon as Red Hat releases the official security updates to prevent potential unauthorized privilege escalation.