Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-25506

30
FAUCET Score

CVE-2026-25506 describes a critical buffer overflow vulnerability in MUNGE versions 0.5 to 0.5.17, impacting Debian and openSUSE distributions. A local attacker can exploit this flaw to leak cryptographic key material from the munged daemon, enabling them to forge arbitrary MUNGE credentials and impersonate any user, including root. With a CVSS score of 7.8 (High), this vulnerability allows for complete compromise of confidentiality, integrity, and availability with low attack complexity. Although no active exploitation or public exploit code has been identified, and community discussion is minimal, the potential impact is severe.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0.5, < 0.5.18CPE matchmatch criteria
cpe:2.3:a:opensuse:munge:*:*:*:*:*:*:*:*
11.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.7HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
LOW
Exploitability Score
1.1
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.30%
Probability of exploitation in next 30 days
EPSS Percentile
22.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0030 is in the 59th percentile among its peer group of 17,061 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (16)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: munge-0:0.5.15-11.el10_1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 10.0 Extended Update SupportFixed in: munge-0:0.5.15-10.el10_0.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: munge-0:0.5.13-3.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Advanced Update SupportFixed in: munge-0:0.5.13-1.el8_2.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportFixed in: munge-0:0.5.13-2.el8_4.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnFixed in: munge-0:0.5.13-2.el8_4.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportFixed in: munge-0:0.5.13-2.el8_6.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceFixed in: munge-0:0.5.13-2.el8_6.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsFixed in: munge-0:0.5.13-2.el8_6.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceFixed in: munge-0:0.5.13-2.el8_8.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsFixed in: munge-0:0.5.13-2.el8_8.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: munge-0:0.5.13-14.el9_7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsFixed in: munge-0:0.5.13-13.el9_0.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsFixed in: munge-0:0.5.13-13.el9_2.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.4 Extended Update SupportFixed in: munge-0:0.5.13-13.el9_4.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.6 Extended Update SupportFixed in: munge-0:0.5.13-13.el9_6.1
View patch

Vendor Advisories (1)

redhatCVE-2026-25506Important

MUNGE: MUNGE has a buffer overflow in message unpacking allows key leakage and credential forgery

Feb 10, 2026

References

access.redhat.com / errata/RHSA-2026:16174
access.redhat.com / errata/RHSA-2026:2918
access.redhat.com / errata/RHSA-2026:2923
access.redhat.com / errata/RHSA-2026:2934
access.redhat.com / errata/RHSA-2026:2949
access.redhat.com / errata/RHSA-2026:2954
access.redhat.com / errata/RHSA-2026:3010
access.redhat.com / errata/RHSA-2026:3011
access.redhat.com / errata/RHSA-2026:3012
access.redhat.com / errata/RHSA-2026:3013
access.redhat.com / errata/RHSA-2026:3032
access.redhat.com / errata/RHSA-2026:3033
access.redhat.com / errata/RHSA-2026:3034
access.redhat.com / security/cve/CVE-2026-25506
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-25506.json
lists.debian.org / debian-lts-announce/2026/02/msg00015.html
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2026/02/10/3
Mailing ListPatchThird Party Advisory
openwall.com / lists/oss-security/2026/02/17/6
Mailing ListThird Party Advisory
github.com / dun/munge/commit/bf40cc27c4ce8451d4b062c9de0b67ec40894812
Patch
github.com / dun/munge/releases/tag/munge-0.5.18
ProductRelease Notes
github.com / dun/munge/security/advisories/GHSA-r9cr-jf4v-75gh
MitigationPatchVendor Advisory