Red Hat has released an Important security update for mrtg in Red Hat Enterprise Linux 10 to fix CVE-2026-72694, a local privilege-escalation flaw caused by improper link resolution, classified as CWE-59. The bug stems from symlink-following chown behavior in the MRTG daemon, allowing a low-privileged local user to manipulate the PID file path and potentially gain unauthorized control over file ownership, with resulting confidentiality and integrity impact but no reported availability impact.
Equivalent advisories and detection coverage have also appeared across downstream enterprise Linux distributions, including Rocky Linux 10, Oracle Linux 10, and AlmaLinux 10, indicating broad package exposure in Linux 10-based environments. Red Hat shipped fixed packages in version mrtg-2.17.10-12.el10_2.1 for multiple architectures, while Tenable plugins for the related vendor notices report the issue as locally exploitable with low privileges required and state that no known exploits are currently available.

Get the actors, campaigns, and ATT&CK mapping behind it.
6 events from the most recent confirmed update back to the earliest known activity.
A Rocky Linux security notice for Rocky Linux 10 reported that a patch for CVE-2026-72694 was published. The notice covers MRTG-related packages and states no known exploits are available.
AlmaLinux issued advisory ALSA-2026-57596 for AlmaLinux 10 and multiple repository variants, covering mrtg and mrtg-selinux packages affected by CVE-2026-72694. The advisory classifies the issue as CWE-59 and states no known exploits are available.
Oracle Linux published security advisory ELSA-2026-57600 for the mrtg package on Oracle Linux 9, addressing CVE-2026-72694. The advisory describes the flaw as locally exploitable and notes that no known exploits are available.
Oracle Linux published security notice ELSA-2026-57596 for mrtg and mrtg-selinux on Oracle Linux 10, addressing CVE-2026-72694. The notice describes the flaw as locally exploitable with low privileges and high confidentiality and integrity impact.
Red Hat published RHSA-2026:57596 for Red Hat Enterprise Linux 10, providing updated mrtg packages version 2.17.10-12.el10_2.1. The advisory says the update fixes CVE-2026-72694, a symlink-following chown issue in the MRTG daemon that can allow local privilege escalation via PID file path manipulation.
The vulnerability CVE-2026-72694 was published as a locally exploitable MRTG flaw associated with symlink-following behavior and privilege escalation risk. Multiple downstream Linux security notices reference this publication date.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
6 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourceaccess.redhat.com
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.