OVERVIEW CVE-2026-39860 is a privilege escalation vulnerability in Nix, a package manager used across Linux and Unix systems. The flaw resides in an incomplete fix for a prior vulnerability (CVE-2024-27297) that failed to properly sanitize symlink handling during fixed-output derivation registration. This affects all sandboxed Linux builds, though macOS builds remain unaffected. SEVERITY The vulnerability carries a CVSS score of 8.4 (HIGH) with a local attack vector requiring low privileges and no user interaction. The attack has system-wide scope, enabling confidentiality and integrity impacts. In multi-user installations where the Nix daemon runs as root, any user permitted to submit builds can exploit this to follow symlinks and overwrite arbitrary files, effectively achieving root-level privilege escalation. EXPLOITATION STATUS There is currently no evidence of active exploitation in the wild, with an EPSS score of 0.00035 indicating very low probability of widespread attack attempts. The vulnerability is not listed on the CISA Known Exploited Vulnerabilities catalog and remains inactive on community hot lists. However, the straightforward nature of the exploit mechanism and the high privileges available to successful attackers warrant prompt patching. Affected organizations should update to patched versions 2.34.5, 2.33.4, 2.32.7, 2.31.4, 2.30.4, 2.29.3, or 2.28.6 immediately.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.18.2, <= 2.18.9CPE matchmatch criteria | cpe:2.3:a:nixos:nix:*:*:*:*:*:*:*:* | ||
>= 2.19.4, <= 2.19.7CPE matchmatch criteria | cpe:2.3:a:nixos:nix:*:*:*:*:*:*:*:* | ||
>= 2.20.5, <= 2.20.9CPE matchmatch criteria | cpe:2.3:a:nixos:nix:*:*:*:*:*:*:*:* | ||
>= 2.21.0, < 2.28.6CPE matchmatch criteria | cpe:2.3:a:nixos:nix:*:*:*:*:*:*:*:* | ||
>= 2.29.0, < 2.29.3CPE matchmatch criteria | cpe:2.3:a:nixos:nix:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.