CVE-2026-4878 is a time-of-check-to-time-of-use (TOCTOU) race condition vulnerability in libcap's cap_set_file() function that enables local privilege escalation. An unprivileged attacker with write access to a parent directory can exploit this flaw to redirect capability updates to attacker-controlled files, potentially injecting or stripping capabilities from unintended executables. The vulnerability has a CVSS score of 6.7 (Medium) with a local attack vector and high complexity. Successful exploitation requires low privileges and user interaction, but impacts all three security attributes—confidentiality, integrity, and availability—through capability manipulation leading to privilege escalation. The attack surface is limited to systems where the attacker already has filesystem write permissions. This vulnerability currently shows no signs of active exploitation in the wild. It is not listed on the Known Exploited Vulnerabilities (KEV) catalog and remains inactive on threat intelligence hotlists. The extremely low EPSS score of 0.00004 indicates minimal practical exploitation likelihood relative to the broader CVE landscape, suggesting it remains primarily a theoretical risk at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:libcap_project:libcap:-:*:*:*:*:*:*:* | ||
4.0CPE matchmatch criteria | cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.