CVE Explorer
CVE-2026-46388
osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. Prior to 5.23.1, an unprivileged attacker can read the contents of an osquery file carve until the carve completes and the temporary files are deleted because in-progress carve directories are not created with private permissions. If the carve targets a directory that the attacker controls, arbitrary file reads are possible, such as sensitive local files. This issue is fixed in version 5.23.1.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 3 assertions
{"cweId":"CWE-279","description":"CWE-279: Incorrect Execution-Assigned Permissions","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f1aa72aaf52c4571aa89523b618b76096c15964bd2fd5d86dd6decc42c161736 · sha256:b0f307d1601fba09… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-379","description":"CWE-379: Creation of Temporary File in Directory with Insecure Permissions","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f1aa72aaf52c4571aa89523b618b76096c15964bd2fd5d86dd6decc42c161736 · sha256:b0f307d1601fba09… · /containers/cna/problemTypes/2/descriptions/0
{"cweId":"CWE-378","description":"CWE-378: Creation of Temporary File With Insecure Permissions","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f1aa72aaf52c4571aa89523b618b76096c15964bd2fd5d86dd6decc42c161736 · sha256:b0f307d1601fba09… · /containers/cna/problemTypes/1/descriptions/0
Affected products and versions
1 source assertion{"product":"osquery","vendor":"osquery","versions":[{"status":"affected","version":"< 5.23.1"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:f1aa72aaf52c4571aa89523b618b76096c15964bd2fd5d86dd6decc42c161736 · sha256:b0f307d1601fba09… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"LOCAL","availabilityImpact":"NONE","baseScore":4.4,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:f1aa72aaf52c4571aa89523b618b76096c15964bd2fd5d86dd6decc42c161736 · sha256:b0f307d1601fba09… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
3 source assertions{"cweId":"CWE-279","description":"CWE-279: Incorrect Execution-Assigned Permissions","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f1aa72aaf52c4571aa89523b618b76096c15964bd2fd5d86dd6decc42c161736 · sha256:b0f307d1601fba09… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-379","description":"CWE-379: Creation of Temporary File in Directory with Insecure Permissions","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f1aa72aaf52c4571aa89523b618b76096c15964bd2fd5d86dd6decc42c161736 · sha256:b0f307d1601fba09… · /containers/cna/problemTypes/2/descriptions/0
{"cweId":"CWE-378","description":"CWE-378: Creation of Temporary File With Insecure Permissions","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f1aa72aaf52c4571aa89523b618b76096c15964bd2fd5d86dd6decc42c161736 · sha256:b0f307d1601fba09… · /containers/cna/problemTypes/1/descriptions/0
Source references
4 source assertions{"name":"https://github.com/osquery/osquery/commit/6dabe9ded33bf9c6fc0f3e37ec364a1cbbd25d68","tags":["x_refsource_MISC"],"url":"https://github.com/osquery/osquery/commit/6dabe9ded33bf9c6fc0f3e37ec364a1cbbd25d68"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f1aa72aaf52c4571aa89523b618b76096c15964bd2fd5d86dd6decc42c161736 · sha256:b0f307d1601fba09… · /containers/cna/references/2
{"name":"https://github.com/osquery/osquery/pull/8961","tags":["x_refsource_MISC"],"url":"https://github.com/osquery/osquery/pull/8961"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f1aa72aaf52c4571aa89523b618b76096c15964bd2fd5d86dd6decc42c161736 · sha256:b0f307d1601fba09… · /containers/cna/references/1
{"name":"https://github.com/osquery/osquery/releases/tag/5.23.1","tags":["x_refsource_MISC"],"url":"https://github.com/osquery/osquery/releases/tag/5.23.1"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f1aa72aaf52c4571aa89523b618b76096c15964bd2fd5d86dd6decc42c161736 · sha256:b0f307d1601fba09… · /containers/cna/references/3
{"name":"https://github.com/osquery/osquery/security/advisories/GHSA-fg78-9q98-62hh","tags":["x_refsource_CONFIRM"],"url":"https://github.com/osquery/osquery/security/advisories/GHSA-fg78-9q98-62hh"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f1aa72aaf52c4571aa89523b618b76096c15964bd2fd5d86dd6decc42c161736 · sha256:b0f307d1601fba09… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.