id: PYSEC-2026-2594 published: "2026-07-13T15:46:28.776087Z" modified: "2026-07-13T16:04:36.061495Z" aliases: - CVE-2026-55426 - GHSA-798h-hpph-m24j summary: Linuxfabrik Monitoring Plugins have local privilege escalation using embedded command details: "### Summary\nWhen a check plugin places user provided input inside a command which is passed to `shell_exec`, an attacker can abuse this to run arbitrary commands. This is mainly dangerous for plugins which are listed in the sudoers file, because this allows an attacker controlling the nagios user to get root privileges.\n\n### Details\nAn example for this is the `restic-check` plugin, where the `--repo` argument is placed inside the command argument of `shell_exec`. As an example, an attacker could use the `--repo` argument `|touch /root/nagios-was-here|`. The full restic command is assembled to the string `restic --json --repo=|touch /root/nagios-was-here| --password-file= check` before it is passed to `shell_exec`. `shell_exec` then splits the command up in three parts at the | boundaries and executes the parts separately, which also executes the embedded command `touch /root/nagios-was-here`.\n\n### PoC\nThis PoC shows how the nagios user can use this to create a file inside `/root`.\n```\nnagios@test-vm:/$ sudo /usr/lib64/nagios/plugins/restic-check --repo '|touch /root/nagios-was-here|'\n```\n\n### Impact\nThe vulnerability is a local privilege escalation.\n\n### Fix\n\n#### Switch from | to an array\nRemove the | split functionality. Instead, modify shell_exec to accept either a string or an array of strings. If an array is provided, the commands are chained together like they currently are when using |. If a string is provided, no split should be performed. You could also introduce a separate function like `shell_exec_with_user_input()` which implements this such that the current shell_exec function can stay like it is.\n\nThis leaves the problem that an attacker can still specify arbitrary arguments inside a command. An example for this would be to use the `--repo` argument `sftp://example.com --cache-dir /tmp`, which would lead to the execution of: `restic --json --repo=sftp://example.com --cache-dir /tmp --password-file=None check`. Please note that this example should mainly highlight the problem in general. To prevent the problem, there is either escaping or again array-syntax. Escaping would use `shlex.quote` to place the user provided argument inside quotes and which also escapes everything which needs to be escaped. Using array syntax would mean providing the full command as an array like `['restic', '--json', '--repo', 'sftp://example.com']`. The array can then be given as-is to `Popen`. With this method, the proposed `shell_exec_with_user_input` would accept an array of array of strings.\n\n### Patches\n\nThe fix follows the array-syntax approach proposed above:\n\n* `linuxfabrik-lib` 5.0.0: `lib.shell.shell_exec()` requires the command as a list of\n arguments (argv) and always runs with `shell=False`. The `|` split functionality, command\n strings and the `shell=` parameter have been removed, so user-provided input can no longer\n break out of a command. `lib.shell.safe_cli_value()` additionally guards positional\n arguments (such as an ssh destination or a ping target) against option injection, and\n `lib.ssh` builds argument lists as well.\n* Linuxfabrik Monitoring Plugins: all plugins assemble their external commands as argv lists\n (commit 23bb570f4). Contained in every release after v5.2.0." affected: - package: name: linuxfabrik-lib ecosystem: PyPI purl: pkg:pypi/linuxfabrik-lib ranges: - type: ECOSYSTEM events: - introduced: "0" - fixed: 5.0.0 versions: - 2.0.0.0 - 2.0.0.7 - 2.1.0.0 - 2.1.0.4 - 2.1.1.15 - 2.1.1.5 - 2.1.1.7 - 2.2.0 - 2.2.1 - 2.3.0 - 2.4.0 - 3.0.0 - 3.1.0 - 3.1.1 - 3.2.0 - 3.3.0 - 3.4.0 - 3.4.1 - 4.0.0 - 4.0.1 - 4.0.2 - 4.1.0 - 4.2.0 - 4.3.0 - 4.4.0 references: - type: WEB url: https://github.com/Linuxfabrik/monitoring-plugins/security/advisories/GHSA-798h-hpph-m24j - type: PACKAGE url: https://github.com/Linuxfabrik/monitoring-plugins - type: PACKAGE url: https://pypi.org/project/linuxfabrik-lib - type: ADVISORY url: https://github.com/advisories/GHSA-798h-hpph-m24j - type: ADVISORY url: https://nvd.nist.gov/vuln/detail/CVE-2026-55426 severity: - type: CVSS_V3 score: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H