# CVE-2026-58086

## Summary

- **CVE ID:** CVE-2026-58086
- **Severity:** HIGH
- **CVSS Score:** 8.1 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H)
- **CWE:** CWE-273
- **Published:** Aug 19, 2026
- **Last Modified:** Aug 27, 2026

## Description

As an inadvertent side effect of an unrelated code change, PRIV_KTRACE was always denied to a jailed root user.  Tracing configured by a jailed root user was therefore not flagged as privileged.

An unprivileged user in a jail that has permission to debug the target process can modify the jailed root user's ktrace(2) flags, or disable tracing outright.  A jailed root user therefore cannot reliably trace unprivileged processes.

## Affected Products

- FreeBSD — FreeBSD (15.1-RELEASE)
- FreeBSD — FreeBSD (15.0-RELEASE)

## References

- [CNA](https://security.freebsd.org/advisories/FreeBSD-SA-26:53.ktrace.asc)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.26%
- **EPSS Percentile:** 17.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._