CVE-2026-23893 is a symlink-following vulnerability in openCryptoki versions 2.3.2 and above, a PKCS#11 library for Linux and AIX. A low-privileged token-group user can exploit this when openCryptoki runs in a privileged context, such as root, by planting symlinks in group-writable token directories. This can lead to privilege escalation or data exposure if an administrator runs a PKCS#11 application or administrative tool that performs chown on files within these directories. The vulnerability has a CVSS score of 6.8 (Medium), indicating a local attack vector with low attack complexity, requiring user interaction. Successful exploitation can result in high confidentiality and integrity impacts, with a low availability impact. Currently, there is no known active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. Despite this, the CVE has garnered significant community discussion with 11 mentions and has been covered in one media article, suggesting notable awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.3.2CPE matchmatch criteria | cpe:2.3:a:opencryptoki_project:opencryptoki:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.