Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-4878

29
FAUCET Score

CVE-2026-4878 is a time-of-check-to-time-of-use (TOCTOU) race condition vulnerability in libcap's cap_set_file() function that enables local privilege escalation. An unprivileged attacker with write access to a parent directory can exploit this flaw to redirect capability updates to attacker-controlled files, potentially injecting or stripping capabilities from unintended executables. The vulnerability has a CVSS score of 6.7 (Medium) with a local attack vector and high complexity. Successful exploitation requires low privileges and user interaction, but impacts all three security attributes—confidentiality, integrity, and availability—through capability manipulation leading to privilege escalation. The attack surface is limited to systems where the attacker already has filesystem write permissions. This vulnerability currently shows no signs of active exploitation in the wild. It is not listed on the Known Exploited Vulnerabilities (KEV) catalog and remains inactive on threat intelligence hotlists. The extremely low EPSS score of 0.00004 indicates minimal practical exploitation likelihood relative to the broader CVE landscape, suggesting it remains primarily a theoretical risk at this time.

Impacted Technologies

VendorProductVersion(s)CPE
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:libcap_project:libcap:-:*:*:*:*:*:*:*
4.0CPE matchmatch criteria
cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*
8.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
9.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
10.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.7MEDIUM

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
0.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.21%
Probability of exploitation in next 30 days
EPSS Percentile
10.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0021 is in the 36th percentile among its peer group of 1,523 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (7)

microsoftpatch availablevia msrc
Product: azl3 libcap 2.69-14 on Azure Linux 3.0Fixed in: 2.69-14
microsoftpatch availablevia msrc
Product: cbl2 libcap 2.60-7 on CBL Mariner 2.0Fixed in: 2.60-8
microsoftpatch availablevia msrc
Product: azl3 libcap 2.69-13 on Azure Linux 3.0Fixed in: 2.69-14
microsoftpatch availablevia msrc
Product: 21190-17086Fixed in: 2.60-8
microsoftpatch availablevia msrc
Product: 21214-17084Fixed in: 2.69-14
microsoftpatch availablevia msrc
Product: 21191-17084Fixed in: 2.69-14
redhatvendor investigatingvia nvd_reference
View patch

Vendor Advisories (1)

microsoft2026-Apr/CVE-2026-4878Moderate

Libcap: libcap: privilege escalation via toctou race condition in cap_set_file()

Apr 2, 2026

References

security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-4878.json
openwall.com / lists/oss-security/2026/04/07/14
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2026/04/07/4
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2026/04/08/9
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2026/04/09/5
ExploitMailing ListThird Party Advisory
openwall.com / lists/oss-security/2026/04/09/6
ExploitMailing ListThird Party Advisory
access.redhat.com / errata/RHSA-2026:12423
access.redhat.com / errata/RHSA-2026:12441
access.redhat.com / errata/RHSA-2026:13285
access.redhat.com / errata/RHSA-2026:14162
access.redhat.com / errata/RHSA-2026:14937
access.redhat.com / errata/RHSA-2026:19130
access.redhat.com / errata/RHSA-2026:19346
access.redhat.com / errata/RHSA-2026:19456
access.redhat.com / errata/RHSA-2026:19458
access.redhat.com / errata/RHSA-2026:20595
access.redhat.com / errata/RHSA-2026:21254
access.redhat.com / errata/RHSA-2026:21275
access.redhat.com / errata/RHSA-2026:22634
access.redhat.com / errata/RHSA-2026:22957
access.redhat.com / errata/RHSA-2026:23233
access.redhat.com / errata/RHSA-2026:23245
access.redhat.com / errata/RHSA-2026:24346
access.redhat.com / errata/RHSA-2026:25044
access.redhat.com / errata/RHSA-2026:25096
access.redhat.com / errata/RHSA-2026:25181
access.redhat.com / errata/RHSA-2026:26542
access.redhat.com / errata/RHSA-2026:27998
access.redhat.com / errata/RHSA-2026:28887
access.redhat.com / errata/RHSA-2026:29197
access.redhat.com / errata/RHSA-2026:30078
access.redhat.com / errata/RHSA-2026:30087
access.redhat.com / errata/RHSA-2026:30088
access.redhat.com / errata/RHSA-2026:30089
access.redhat.com / errata/RHSA-2026:34098
access.redhat.com / errata/RHSA-2026:39981
access.redhat.com / errata/RHSA-2026:7473
Vendor Advisory
access.redhat.com / security/cve/CVE-2026-4878
Vendor Advisory
bugzilla.redhat.com / show_bug.cgi
Permissions Required
bugzilla.redhat.com / show_bug.cgi
Issue TrackingVendor Advisory