CYBERSECURITYTRACKER
TRACKING
Permanent story citation

CVE-2026-100310: GNU libextractor < 1.16 Privilege Escalation via LIBEXTRACTOR_PREFIX

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 8635

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-100310: GNU libextractor < 1.16 Privilege Escalation via LIBEXTRACTOR_PREFIX

GNU libextractor before version 1.16 contains a local privilege escalation vulnerability (CVE-2026-100310) stemming from an untrusted search path. The vulnerability allows attackers to manipulate the LIBEXTRACTOR_PREFIX environment variable to load malicious plugins during the plugin discovery process.

Why it matters: Organizations and developers using GNU libextractor below 1.16 should upgrade immediately, as local attackers can leverage this flaw to execute code with elevated privileges on affected systems.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary