CVE-2026-73973: Linuxfabrik Monitoring Plugins: Arbitrary root file disclosure via unconfined --filename in logfile plugin (sudoers LPE)

Published Aug 18, 2026
·
Updated

Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, Nagios, and related systems. Prior to version 7.0.0, check-plugins/logfile/logfile accepted a free-form --filename path and opened it as root when invoked through the shipped nagios or icinga sudoers allowlist, without confining the resolved path to /var/log. An attacker who controls the monitoring account can select a root-readable file such as /etc/shadow and use --warning-regex . while leaving SUPPRESSOUTPUT false, causing each nonempty line to be collected in warnmatches and returned through lib.base.oao(). The vulnerable flow passes the expanded scanpath directly to open(), and neither real-path containment nor an allowlist protects the sink. The same fix also confines mysql-logfile and openvpn-client-list paths, allows only documented log roots, and resolves symlinks and parent-directory traversal before checking containment. This issue is fixed in version 7.0.0.

Affected Software

4 affected components
Linuxfabrik Linuxfabrik Monitoring Plugins<7.0.0
check-plugins/logfile/logfile<7.0.0
check-plugins/mysql-logfile/mysql-logfile<7.0.0
check-plugins/openvpn-client-list/openvpn-client-list<7.0.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Linuxfabrik Monitoring Plugins (check-plugins/logfile/logfile) to a version that resolves this vulnerability.

    Fixed in 7.0.0
  2. Upgrade

    Upgrade Linuxfabrik Monitoring Plugins (mysql-logfile) to a version that resolves this vulnerability.

    Fixed in 7.0.0
  3. Upgrade

    Upgrade Linuxfabrik Monitoring Plugins (openvpn-client-list) to a version that resolves this vulnerability.

    Fixed in 7.0.0

Event History

Aug 18, 2026
CVE Published
via MITRE·09:12 PM
Data Sourced
via MITRE·09:12 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can realistically exploit this issue?

Systems are exposed when a user can control the monitoring account and invoke the affected plugins through the shipped nagios or icinga sudoers allowlist. Exploitation is local and requires low privileges, but no user interaction.

2

Is the default shipped sudoers configuration affected?

The vulnerable behavior is present in versions before 7.0.0 when logfile can be run as root through the shipped sudoers configuration. The unrestricted --filename argument is not confined to /var/log, and the same remediation also applies path confinement to mysql-logfile and openvpn-client-list.

3

What should be done if patching cannot happen immediately?

Upgrade to version 7.0.0. If an immediate upgrade is not possible, do not allow the monitoring account to invoke these plugins as root with attacker-controlled arguments, particularly --filename.

4

How can I look for signs of exploitation?

Review invocations of logfile for --filename values outside permitted log directories, including paths containing parent-directory traversal or symlinks, and inspect plugin output for unexpected content from root-readable files. A successful attempt can return nonempty file lines as warning matches when --warning-regex . is used and output is not suppressed.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203