CVE-2026-58302: LinuxCNC rtapi_app Local Privilege Escalation
LinuxCNC's rtapi_app component, which runs with root privileges, loads software modules based on user input without properly validating the file path. An attacker without special privileges can exploit path traversal techniques to point the application toward a malicious library file they control, causing the privileged process to load and execute it. This results in immediate root-level compromise of the system. The vulnerability affects LinuxCNC versions before 2.9.9.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 8.4 HIGH · CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Weaknesses (CWE)
- CWE-22
- Affected products
- 0 configuration(s)
- Published / Modified
- 2026-06-30 / 2026-06-30
NVD description (verbatim)
rtapi_app in linuxcnc-uspace in LinuxCNC before 2.9.9 allows privilege escalation. It is installed SUID root and loads shared library modules via dlopen() by using a user-supplied module name. Insufficient validation of the module name allows path traversal, enabling an unprivileged local user to load an arbitrary shared library. Because the process retains elevated privileges during module loading, this results in local privilege escalation to root.
4 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-58302 is a local privilege escalation vulnerability in rtapi_app, a setuid-root binary in LinuxCNC-uspace. The vulnerability stems from insufficient path validation when loading shared library modules via dlopen(). An attacker supplies a crafted module name containing path traversal sequences (e.g., '../../') to redirect module loading to an arbitrary shared library under their control. Because rtapi_app retains elevated privileges throughout the module-loading phase, the attacker's library executes with root context. The flaw is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory). Exploitation requires only local access and no special privileges or user interaction.
Business impact
Successful exploitation grants an unprivileged local user complete root access to the affected system. In manufacturing and industrial control environments where LinuxCNC is commonly deployed (machine tools, CNC systems), this translates to direct control over physical machinery, data, and network connectivity. An attacker could alter production parameters, steal intellectual property, sabotage equipment, or use the compromised system as a pivot point to attack adjacent industrial infrastructure. Organizations relying on LinuxCNC should treat this as a critical risk to operational technology security.
Affected systems
LinuxCNC versions prior to 2.9.9 are affected, specifically the linuxcnc-uspace distribution variant. The vulnerability is specific to systems where rtapi_app is installed with setuid-root permissions. LinuxCNC runs primarily on Linux systems used for numerical control and computer-aided manufacturing; typical deployments involve dedicated industrial machines, workstations, and embedded controllers in manufacturing environments.
Exploitability
This vulnerability is straightforward to exploit. No special privileges, credentials, or user interaction are required—only local shell access. An attacker can craft a malicious shared library, then invoke rtapi_app with a path-traversal module name pointing to that library. The absence of complexity in exploitation (AC:L in the CVSS vector) and the immediate privilege escalation to root make this a high-risk flaw from an operational perspective. The vulnerability is not currently listed in CISA's Known Exploited Vulnerabilities catalog, but the simplicity of exploitation warrants rapid patching regardless.
Remediation
Upgrade LinuxCNC to version 2.9.9 or later. Organizations unable to upgrade immediately should restrict local shell access to rtapi_app by limiting the user accounts permitted to invoke it, and consider disabling or isolating affected systems until patching is feasible. Verify that rtapi_app retains setuid-root permissions only where functionally necessary.
Patch guidance
The fix is available in LinuxCNC 2.9.9 and later versions. Patch by updating your LinuxCNC installation through your distribution package manager or by downloading the latest source from the official LinuxCNC repository and rebuilding. Confirm the update with version checks (e.g., rtapi_app --version or equivalent). If using a vendor-packaged version, check your vendor's update schedule. Test patched systems in a non-production environment before full deployment to ensure compatibility with your CNC configurations.
Detection guidance
Monitor system logs for failed or unusual module-load attempts by rtapi_app. Watch for suspicious dlopen() calls with path-traversal sequences in process arguments and environment variables. Endpoint Detection & Response (EDR) systems should flag privilege escalation events where rtapi_app transitions from unprivileged user to root. File-integrity monitoring on shared library directories can detect unauthorized library placement. Review process accounting logs for unexpected rtapi_app invocations by regular users. Additionally, audit which user accounts have permission to execute rtapi_app and ensure principle of least privilege is enforced.
Why prioritize this
HIGH priority (CVSS 8.4) warrants immediate action. The combination of ease of exploitation (no privileges required, straightforward path traversal), direct privilege escalation to root, and deployment in safety-critical industrial control systems elevates risk significantly. While not yet in the KEV catalog, the simplicity and impact justify treating this as a production emergency in any environment running LinuxCNC.
Risk score, explained
CVSS 3.1 score of 8.4 (HIGH) reflects: Attack Vector Local (AV:L) — requires local system access; Attack Complexity Low (AC:L) — no special conditions required; Privileges Required None (PR:N) — unauthenticated local user can exploit; User Interaction None (UI:N) — no user action needed; Scope Unchanged (S:U) — impact limited to the affected system; Confidentiality High (C:H), Integrity High (I:H), Availability High (A:H) — full compromise of system assets. The high confidentiality, integrity, and availability impact combined with trivial exploitability justifies the 8.4 score and HIGH severity classification.
Frequently asked questions
Can this vulnerability be exploited remotely?
No. CVE-2026-58302 requires local system access; it cannot be exploited over a network. An attacker must have shell access or the ability to run commands on the affected LinuxCNC system.
Do I need special user privileges to exploit this?
No. An unprivileged local user can exploit this vulnerability. No special group membership, sudo access, or elevated privileges are needed to trigger the exploit.
How quickly should I patch?
Immediately. The combination of ease of exploitation and severity (full root compromise) makes this a critical priority. Patch within days, not weeks, especially if the system is in a production manufacturing environment.
What if I can't patch LinuxCNC immediately?
Restrict local shell access to only trusted users who need rtapi_app. Disable setuid-root on rtapi_app if your workload allows, run it under a lower-privileged service account, or isolate the affected system from untrusted networks and users until patching is complete.
This analysis is provided for informational purposes and reflects publicly available information as of the publication date. SEC.co does not warrant the accuracy, completeness, or timeliness of information herein. Patch version numbers and vendor availability should be independently verified against official vendor advisories before deployment. Organizations should conduct their own risk assessment and testing in non-production environments before applying patches. This content does not constitute legal, regulatory, or professional advice. Source: NVD (public-domain), retrieved 2026-08-08. Analysis generated by SEC.co (claude-haiku-4-5).
Weaknesses (CWE)
Related vulnerabilities
- CVE-2016-20076HIGHWordPress Simple-Backup 2.7.11 Unauthenticated File Access & Deletion Vulnerability
- CVE-2016-20081HIGHHB Audio Gallery Lite Path Traversal Vulnerability – Unauthenticated File Download
- CVE-2017-20248HIGHApptha Slider Gallery Path Traversal Vulnerability
- CVE-2017-20250HIGHMac Photo Gallery 3.0 Path Traversal File Download Vulnerability
- CVE-2018-25408HIGHOpen ISES Project Path Traversal Vulnerability (High Severity)
- CVE-2024-32729HIGHPath Traversal in QuantumCloud Conversational Forms for ChatBot (CVSS 7.5)
- CVE-2024-40646HIGHVertex Path Traversal Vulnerability – Remote File Access Risk
- CVE-2025-60223HIGHWPBot Pro Arbitrary File Deletion Vulnerability – HIGH Risk Exploit