Sploitus

CVE-2026-11837

1 known exploit for CVE-2026-11837

A local privilege escalation vulnerability was found in the ansible.posix authorized_key module. The module's keyfile() function uses os.chown() instead of os.lchown() and opens files without O_NOFOLLOW when managing SSH authorized keys. An unprivileged local user can pre-stage symbolic links in their ~/.ssh directory to redirect file ownership changes to arbitrary system paths when an operator runs the authorized_key task as root, leading to local privilege escalation.

Affected products
Ansible.Posix
CVSS 3.1
7.3 HIGH
EPSS
0.2% (5th percentile)
Weakness
CWE-59
NVD status
Awaiting Analysis
Published
2026-06-10

Workaround

The following practices would help for avoiding exposure and mitigate this flaw: 1) Do not run the ansible.posix authorized_key module with elevated privileges against untrusted user accounts. 2) Validate that target user home directories do not contain unexpected symbolic links before running playbooks.

CVE-2026-11837 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2026-11837

Proof-of-concept code and exploit modules indexed by Sploitus