SYS::ONLINE
Wasteland.
Briefs2280
Issues25
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2015-5287 2026-08-26

CVE-2015-5287: Red Hat ABRT Symlink Privilege Escalation Added to CISA KEV

"CISA added CVE-2015-5287, a local privilege escalation flaw in Red Hat's Automatic Bug Reporting Tool, to the Known Exploited Vulnerabilities catalog on 2026-08-26 with a remediation deadline of 2026-09-09."

CISA added CVE-2015-5287, a local privilege escalation flaw in Red Hat's Automatic Bug Reporting Tool, to the Known Exploited Vulnerabilities catalog on 2026-08-26 with a remediation deadline of 2026-09-09.

What Is It

The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before version 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name. NVD cites /var/tmp/abrt/abrt-hax-coredump and /var/spool/abrt/abrt-hax-coredump as demonstrated targets. The weakness is classified as CWE-59 (link following).

NVD scores it CVSS 3.1 base 7.8 (HIGH), vector AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, local attack vector, low complexity, low privileges required, no user interaction, and high confidentiality, integrity, and availability impact.

Why It Matters

CISA's KEV listing confirms active exploitation. The SSVC assessment recorded by CISA marks exploitation as active, automatable as no, and technical impact as total. Public exploit material exists and is referenced by NVD, including an Exploit-DB entry and an oss-security posting.

CISA further notes the affected product may be end-of-life or end-of-service, and advises users to discontinue use and/or transition to a supported version.

What's Vulnerable

Per NVD's CPE configuration:

Patch Status

Fixed in ABRT 2.7.1. The upstream fix is commit 3c1b60cfa62d39e5fff5a53a5bc53dae189e740e in the abrt repository, and Red Hat published errata RHSA-2015-2505.

CISA's required action: apply mitigations per vendor instructions in accordance with BOD 26-04 (Prioritizing Security Updates Based on Risk) and CISA's Forensics Triage Requirements; follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure. Known ransomware campaign use is listed as Unknown.

Sources