Red Hat released security updates for the kbd package in RHEL 9 and RHEL 10 to fix CVE-2026-72693, a local privilege escalation flaw in the openvt utility that can lead to passwordless root login. The bug affects the privileged openvt -u login path and stems from incorrect process owner verification: openvt trusted the ownership of the TTY referenced through /proc/<pid>/fd/0 instead of validating the owning process. In vulnerable deployments, including documented kbrequest/init configurations such as kb::kbrequest:/usr/bin/openvt -us, an unprivileged local user could reach login -f root and gain full system compromise.
Red Hat rated the issue Moderate in its advisories RHSA-2026:57597 for RHEL 10 and RHSA-2026:57610 for RHEL 9, while the original report assigned a CVSS 7.8 High score because exploitation requires only local access and a specific privileged configuration. Updated kbd packages were issued across multiple architectures and support channels, including builds such as 2.6.4-8.el10_2 for RHEL 10 and 2.4.0-12.el9_8 for RHEL 9. Downstream coverage also appeared in AlmaLinux 10 detection content, indicating the flaw affects related kbd, kbd-legacy, and kbd-misc packages in compatible enterprise Linux environments.

Get the actors, campaigns, and ATT&CK mapping behind it.
5 events from the most recent confirmed update back to the earliest known activity.
The Tenable plugin states that the patch for CVE-2026-72693 was published on August 20, 2026, referencing AlmaLinux advisory ALSA-2026:57597 derived from Red Hat's fix stream.
On 2026-08-20, Red Hat issued RHSA-2026:57610 for Red Hat Enterprise Linux 9, releasing updated kbd packages including version 2.4.0-12.el9_8 to address CVE-2026-72693.
On 2026-08-20, Red Hat issued RHSA-2026:57597 for Red Hat Enterprise Linux 10, releasing updated kbd packages version 2.6.4-8.el10_2 to fix the openvt privilege escalation flaw.
The Tenable plugin states that CVE-2026-72693 was published on August 11, 2026. The vulnerability is a local privilege escalation flaw in openvt that can enable passwordless root login in affected deployments.
A Red Hat Bugzilla report described CVE-2026-72693 as a local privilege escalation in kbd's openvt utility caused by trusting TTY ownership from /proc/<pid>/fd/0 instead of validating the owning process. The report included exploitation details, mitigations, and a proposed code fix.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
5 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.