CVE-2026-46388CWE-279CWE-378CWE-379

osquery: Unprivileged users can temporarily read file carve contents

Medium · published July 10, 2026

CVSS v3.1
4.4
EPSS
0%
Percentile
2.6
In the wild
Unconfirmed
What it is

osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. Prior to 5.23.1, an unprivileged attacker can read the contents of an osquery file carve until the carve completes and the temporary files are deleted because in-progress carve directories are not created with private permissions. If the carve targets a directory that the attacker controls, arbitrary file reads are possible, such as sensitive local files. This issue is fixed in version 5.23.1.

The record
Technical detail
CVSS v3.1
4.4 · MEDIUM
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00126 · 2.6th percentile
Weaknesses
CWE-279 · Incorrect Execution-Assigned Permissions; CWE-378 · Creation of Temporary File With Insecure Permissions; CWE-379 · Creation of Temporary File in Directory with Insecure Permissions
Published
2026-07-10T14:44Z
EPSS history
Timeline
  • 10 JUL 14:44Z
    osquery: Unprivileged users can temporarily read file carve contents
    cvelistv5