THREAT OPS › Threat News › [NVD] CVE-2026-54231 (MEDIUM 5.5) — A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The event script queries the systemd journal for log entries matching the crashed process and writes the results to files in the dump directory without sanitizing embedded cont
[NVD] CVE-2026-54231 (MEDIUM 5.5) — A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The event script queries the systemd journal for log entries matching the crashed process and writes the results to files in the dump directory without sanitizing embedded cont
CVE-2026-54231 CVSS: 5.5 MEDIUM Published: 2026-06-13T03:16:21.877
A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The event script queries the systemd journal for log entries matching the crashed process and writes the results to files in the dump directory without sanitizing embedded control characters. A local user can inject arbitrary co
MITRE ATT&CK techniques
- Content InjectionT1659
Indicators of compromise
- CVE-2026-54231cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-54231