# CVE-2026-72693

## Summary

- **CVE ID:** CVE-2026-72693
- **Severity:** HIGH
- **CVSS Score:** 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-284
- **Published:** Aug 11, 2026
- **Last Modified:** Sep 15, 2026

## Description

`openvt -u` is intended to identify the owner of the current VT and then execute `login` as that user from a privileged context. In the documented `kbrequest`/init usage, the ownership test in `authenticate_user()` relies on `stat("/proc/<pid>/fd/0")`. `stat()` on `/proc/<pid>/fd/0` follows the symlink to the underlying TTY device node. As a result, `buf.st_uid` reflects the owner of the TTY node rather than the owner of the process holding the file descriptor. If the TTY owner returns to `root` or the getty owner after logout while an unprivileged process still has `fd 0` attached to that TTY, the check can incorrectly treat that process as belonging to the privileged console owner. Once that check succeeds, the `-u` path executes a passwordless login as the selected user. In the documented `kbrequest`/init deployment using `openvt -us`, this can result in passwordless `login -f root` on the spawned VT. This report establishes that privilege escalation path for that documented deployment; it does not claim equivalent reachability for deployments that do not use `openvt -u` from a privileged `kbrequest`/init path.

## Affected Products

- Red Hat — Red Hat Hardened Images (2.10.0-2.hum1)
- Red Hat — Red Hat Enterprise Linux 10 (0:2.6.4-8.el10_2)
- Red Hat — Red Hat Enterprise Linux 9 (0:2.4.0-12.el9_8)
- Red Hat — Red Hat OpenShift Container Platform 4.22 (4.22.9.8.202608251819-0)
- Red Hat — Red Hat OpenShift Container Platform 4.22 (4.22.9.8.202609081748-0)

## References

- [CNA](https://access.redhat.com/security/cve/CVE-2026-72693)
- [CNA](https://bugzilla.redhat.com/show_bug.cgi?id=2462115)
- [CNA](https://access.redhat.com/errata/RHSA-2026:41136)
- [CNA](https://access.redhat.com/errata/RHSA-2026:57597)
- [CNA](https://access.redhat.com/errata/RHSA-2026:57610)
- [CNA](https://access.redhat.com/errata/RHSA-2026:60440)
- [CNA](https://access.redhat.com/errata/RHSA-2026:66357)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.11%
- **EPSS Percentile:** 1.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._