CVE-2026-7867 is an incorrect authorization vulnerability in UDisks2's handling of the as-user option of the org.freedesktop.UDisks2.Filesystem.Mount() D-Bus method. UDisks2 does not correctly validate that the caller is authorized to request mounting on behalf of the supplied user identity. A low-privileged local user with an active console session can spoof the as-user parameter and influence the mount path such that a filesystem is mounted for an arbitrary, including privileged, account without the expected PolicyKit authorization behavior. This can enable mount-point injection and manipulation of mount namespaces visible to privileged users.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a Bash-based local privilege escalation PoC suite for CVE-2026-7867 affecting udisks2 on Linux. The core exploit idea is consistent across the scripts: prepare a loopback ext4 filesystem containing a SUID-root helper, register it in /etc/fstab with x-udisks-auth, then as an unprivileged user invoke the system D-Bus method org.freedesktop.UDisks2.Filesystem.Mount on the corresponding /org/freedesktop/UDisks2/block_devices/<loopdev> object while supplying the option as-user=root. The scripts claim this causes identity confusion in udisks2’s authorization flow, bypassing expected PolicyKit checks and allowing a root-context mount. If the mounted filesystem preserves the SUID bit, executing the helper yields EUID 0 or a root shell. Structure: README.md is a detailed research write-up describing the vulnerability, attack flow, affected component, and disclosure timeline. disk2root.sh is the main operational exploit wrapper: it supports root-assisted setup, unprivileged exploit execution, and cleanup. It compiles a C SUID payload, creates a loop image, injects the payload, edits /etc/fstab, waits for udisks2 to recognize the loop device, then runs the exploit phase as a target user. The poc/ directory contains supporting validation scripts: setup_lpe_env.sh and cleanup_lpe_env.sh build and tear down a lab environment; f2_mount_as_user_bypass.sh demonstrates the mount bypass; f2_final.sh performs end-to-end verification; f2_check_nosuid.sh and f2_suid_test.sh test whether nosuid or mount semantics prevent full privilege escalation. Capabilities: local D-Bus interaction with UDisks2, loop device creation, filesystem image preparation, fstab manipulation, test-user creation, vulnerable mount triggering, mount verification, and SUID payload execution. This is a real exploit repository rather than a detector, and its payload is basic but functional, making the maturity OPERATIONAL rather than mere POC.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A local privilege-escalation vulnerability in udisks2 caused by spoofing of the as-user option. It affects installed udisks2 packages on Red Hat Enterprise Linux 10 systems covered by RHSA-2026:64798 and is rated Important by Red Hat.
A locally exploitable vulnerability requiring low privileges that can result in high confidentiality, integrity, and availability impact on affected openSUSE 16.0 UDisks2 packages.
A high-impact local vulnerability in the udisks2 package set on Amazon Linux 2023. It requires low privileges and could affect confidentiality, integrity, and availability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.