THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-63404 — Faktory is a language-agnostic background job server. In versions prior to 1.10.0, the embedded Redis bootstrapper is vulnerable to an insecure temporary file flaw that lets a local unprivileged user hijack the Redis configuration and escalate to root. It writes its startup confi

[NVD] CVE-2026-63404 — Faktory is a language-agnostic background job server. In versions prior to 1.10.0, the embedded Redis bootstrapper is vulnerable to an insecure temporary file flaw that lets a local unprivileged user hijack the Redis configuration and escalate to root. It writes its startup confi

mednvdPublished 2026-08-25

CVE-2026-63404 CVSS: None Published: 2026-08-25T22:17:04.760

Faktory is a language-agnostic background job server. In versions prior to 1.10.0, the embedded Redis bootstrapper is vulnerable to an insecure temporary file flaw that lets a local unprivileged user hijack the Redis configuration and escalate to root. It writes its startup configuration to a fixed, predictable, world-writable path, /t

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-63404