Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-75092
Red Hat Red Hat Enterprise Linux 9 — Leapp-repository: leapp-upgrade-el9toel10: leapp-upgrade-el9toel10: scan_mysql runs mysqld --validate-config as root and can load mysql-writable plugins
AV AC PR UI S C I A CVSS EPSS %ile KEV
L L L R U H H H 7.3 .0013 2.1 —
AFFECTED
Product Versions Fixed
Red Hat Enterprise Linux 9 unspecified 0:0.24.0-1.el9_8.1
Red Hat Enterprise Linux 9.6 Extended Update Support unspecified 0:0.22.0-1.el9_6.2
Red Hat Enterprise Linux 8 unspecified —
Red Hat OpenStack Platform 17.1 unspecified —
TIMELINE
Aug 17 Reserved by redhat
Sep 15 PATCH SHIPPED — CVE-2026-75092 (Red Hat Enterprise Linux 9). Fixed in Red Hat Enterprise Linux 9 0:0.24.0-1.el9_8.1.
Sep 15 Published (CNA: redhat)
Description
A privilege escalation flaw was found in the scan_mysql actor of leapp-upgrade-el9toel10 (provided by leapp-repository). During RHEL 9 to RHEL 10 upgrades, the actor runs:
mysqld --validate-config --log-error-verbosity=2 directly as root in the Leapp actor context, bypassing the packaged MySQL systemd unit that normally starts the daemon as User=mysql.
A process compromised as the mysql OS identity can write a version-2 persisted configuration (mysqld-auto.cnf) and a malicious shared object into /var/lib/mysql (a directory owned by mysql). That persisted map can set plugin_dir to /var/lib/mysql and early_plugin_load (or related loader options such as plugin_load / plugin_load_add) so MySQL loads the attacker-controlled object during configuration validation. Plugin loading can reach dlopen() before MySQL’s runtime-user check and before plugin-symbol validation.
When an administrator subsequently runs the documented Leapp preupgrade or upgrade workflow, attacker-controlled code can execute as UID 0 with a full capability set in an unconfined SELinux domain (unconfined_t). The attack does not require write access to the default system plugin path under /usr; redirecting plugin_dir via mysql-owned persisted state is sufficient. Ordinary SQL privileges alone (including highly privileged SQL accounts) are not a sufficient startpoint — OS-level execution as the mysql service identity is required, plus later administrator invocation of Leapp.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| August 17, 2026 | Reserved | Reserved by redhat |
| September 15, 2026 | PATCH SHIPPED | PATCH SHIPPED — CVE-2026-75092 (Red Hat Enterprise Linux 9). Fixed in Red Hat Enterprise Linux 9 0:0.24.0-1.el9_8.1. |
| September 15, 2026 | Published | Published (CNA: redhat) |
Affected
Affected products and packages — 4 rows
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Red Hat | Red Hat Enterprise Linux 9 | — | — | 0:0.24.0-1.el9_8.1 |
| Red Hat | Red Hat Enterprise Linux 9.6 Extended Update Support | — | — | 0:0.22.0-1.el9_6.2 |
| Red Hat | Red Hat Enterprise Linux 8 | — | — | — |
| Red Hat | Red Hat OpenStack Platform 17.1 | — | — | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-75092 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.