As cited
Copy frozen at (site build).
vulnerabilities
CVE-2026-100310: GNU libextractor < 1.16 Privilege Escalation via LIBEXTRACTOR_PREFIX
GNU libextractor before version 1.16 contains a local privilege escalation vulnerability (CVE-2026-100310) stemming from an untrusted search path. The vulnerability allows attackers to manipulate the LIBEXTRACTOR_PREFIX environment variable to load malicious plugins during the plugin discovery process.
Why it matters: Organizations and developers using GNU libextractor below 1.16 should upgrade immediately, as local attackers can leverage this flaw to execute code with elevated privileges on affected systems.
- Source published
- First seen by Cybersecurity Tracker