boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-75092

Red Hat Red Hat Enterprise Linux 9 — Leapp-repository: leapp-upgrade-el9toel10: leapp-upgrade-el9toel10: scan_mysql runs mysqld --validate-config as root and can load mysql-writable plugins
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   L   R  U  H  H  H    7.3   .0013    2.1     —
AFFECTED
  Product                                               Versions     Fixed
  Red Hat Enterprise Linux 9                            unspecified  0:0.24.0-1.el9_8.1
  Red Hat Enterprise Linux 9.6 Extended Update Support  unspecified  0:0.22.0-1.el9_6.2
  Red Hat Enterprise Linux 8                            unspecified  —
  Red Hat OpenStack Platform 17.1                       unspecified  —
TIMELINE
  Aug 17  Reserved by redhat
  Sep 15  PATCH SHIPPED — CVE-2026-75092 (Red Hat Enterprise Linux 9). Fixed in Red Hat Enterprise Linux 9 0:0.24.0-1.el9_8.1.
  Sep 15  Published (CNA: redhat)
CWE-250 · CNA: redhat · CVSS v3.1 · 7 references · NVD status: Awaiting Analysis

Description

A privilege escalation flaw was found in the scan_mysql actor of leapp-upgrade-el9toel10 (provided by leapp-repository). During RHEL 9 to RHEL 10 upgrades, the actor runs: mysqld --validate-config --log-error-verbosity=2 directly as root in the Leapp actor context, bypassing the packaged MySQL systemd unit that normally starts the daemon as User=mysql. A process compromised as the mysql OS identity can write a version-2 persisted configuration (mysqld-auto.cnf) and a malicious shared object into /var/lib/mysql (a directory owned by mysql). That persisted map can set plugin_dir to /var/lib/mysql and early_plugin_load (or related loader options such as plugin_load / plugin_load_add) so MySQL loads the attacker-controlled object during configuration validation. Plugin loading can reach dlopen() before MySQL’s runtime-user check and before plugin-symbol validation. When an administrator subsequently runs the documented Leapp preupgrade or upgrade workflow, attacker-controlled code can execute as UID 0 with a full capability set in an unconfined SELinux domain (unconfined_t). The attack does not require write access to the default system plugin path under /usr; redirecting plugin_dir via mysql-owned persisted state is sufficient. Ordinary SQL privileges alone (including highly privileged SQL accounts) are not a sufficient startpoint — OS-level execution as the mysql service identity is required, plus later administrator invocation of Leapp.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
August 17, 2026ReservedReserved by redhat
September 15, 2026PATCH SHIPPEDPATCH SHIPPED — CVE-2026-75092 (Red Hat Enterprise Linux 9). Fixed in Red Hat Enterprise Linux 9 0:0.24.0-1.el9_8.1.
September 15, 2026PublishedPublished (CNA: redhat)

Affected

Affected products and packages — 4 rows
VendorProduct / PackageEcosystemVersion introducedFixed
Red HatRed Hat Enterprise Linux 9——0:0.24.0-1.el9_8.1
Red HatRed Hat Enterprise Linux 9.6 Extended Update Support——0:0.22.0-1.el9_6.2
Red HatRed Hat Enterprise Linux 8———
Red HatRed Hat OpenStack Platform 17.1———

Weaknesses

CWE-250

References (7)

Related

Authoritative record: CVE-2026-75092 at cve.org

Vendors: red hat

Weaknesses: CWE-250

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-75092 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.