Skip to content
VulniPulse
Highest advisory severityMedium 1 vendor · 1 advisory

CVE-2026-74796

CVE-2026-74796: 1 tracked advisory record across Red Hat. Compare vendor sources.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Red Hat

1 advisory
  • Advisory severityMedium6.1

    Medium [CVE-2026-74796] Arbitrary file write via symlink following path traversal

    CVE-2026-74796Source published Source updated

    OpenTofu before 1.11.7 fails to validate existing symlinks in the provider cache directory during initialization. Attackers can place a malicious symlink in a trusted working directory to cause tofu init to write provider package contents to arbitrary filesystem locations outside the working tree. A flaw was found in OpenTofu. This vulnerability allows attackers to exploit a symlink following path traversal during the initialization process. This could lead to unauthorized modification of files on the system. This Moderate flaw in OpenTofu allows for arbitrary file writes via symlink following during initialization. However, Red Hat products are not affected by this vulnerability as the vulnerable code is not present. Red Hat severity: Moderate — CVSS 6.1…

    Affected products in this advisory
    No product details extracted. Check the source bulletin.
    Source-reported affected versions
    • < 1.11.7
    Source-reported fixed versions
    No fixed-version detail extracted. This does not mean no fix exists.
    Mitigation guidance
    No mitigation guidance extracted; consult the source.

Android app · Google Play

Monitor future Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery