LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2015-5287: Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Aug 26, 2026
Elevated⚠ Actively exploited (CISA KEV)
Elevated
Severity
Active
CISA KEV
No
Ransomware use
Sep 9, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2015-5287 to its Known Exploited Vulnerabilities catalog on Aug 26, 2026, with a federal patch deadline of Sep 9, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Red Hat Automatic Bug Reporting Tool (ABRT) contains a privilege escalation vulnerability that could allow local users with certain permissions to gain privileges via a symlink attack on a file with a…

CVE-2015-5287 is a local privilege-escalation flaw in the Red Hat Automatic Bug Reporting Tool (ABRT). A user who already has limited access on a system can abuse how ABRT handles a file with a predictable name—via a symlink attack—to obtain higher privileges. That matters because ABRT has historically been present on many Red Hat and related Linux hosts used for crash reporting; successful abuse can turn a foothold into full administrative control of the machine. Impacted builds may be end-of-life or end-of-service, so teams should treat continued use as elevated risk and plan to move off unsupported software.

Public technical detail is limited to the class of issue described by CISA. Confirm exact package versions, fixed releases, and configuration caveats only against the current Red Hat (or successor) vendor advisory before you act.

How it works

The weakness is a classic local privilege-escalation pattern built around insecure handling of a predictable filename and symbolic links. ABRT performs privileged operations on paths that an unprivileged or partially privileged local user can influence. By placing a symlink where ABRT expects a regular file (or otherwise racing the tool’s use of that predictable name), the attacker can cause privileged code to operate on a target of the attacker’s choosing—commonly resulting in overwritten files, altered permissions, or execution in a higher-privilege context.

No remote network exploit path is described in the given facts; the attacker needs local access and the ability to create or manipulate the relevant filesystem objects. Exact race windows, path names, and required group memberships are not specified here and must be taken from the vendor advisory rather than assumed.

Am I affected? How to find it in your systems

ABRT is a crash-reporting component typically found on Red Hat Enterprise Linux and closely related distributions where automatic bug reporting was enabled. It is not a network-facing service in the usual sense; risk is concentrated on hosts where the ABRT packages and services are installed and where untrusted or multi-user local access exists (shared jump hosts, developer workstations, containers that mount host paths, etc.).

How to remediate

Patch first. Apply the vendor-supplied update for ABRT that addresses CVE-2015-5287, following Red Hat’s (or your distribution’s) instructions and change-control process. After installation, verify the package version and restart or disable any ABRT services as the advisory directs so the vulnerable code path is no longer loaded.

If you can't patch immediately

Compensating controls only buy time; they do not replace the vendor fix or a supported replacement.

If your data may have been exposed

Actively exploited local privilege-escalation flaws are often used after an initial compromise to deepen access, move laterally, or stage data theft. Known ransomware use is not documented for this CVE in the provided facts, but any host that ran vulnerable ABRT with untrusted local users should be reviewed for unauthorized accounts, persistence, and sensitive data access. If you believe credentials or personal data may have left your environment, follow your incident-response process, rotate secrets that could have been reached from the host, and consider checking whether your email addresses appear in known breach corpora via a free exposure scan as one quick external signal—not a substitute for host forensics.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedRed Hat · Automatic Bug Reporting Tool
Added to CISA KEVAug 26, 2026
Federal patch deadlineSep 9, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities