github.com
https://github.com/osquery/osquery/commit/6dabe9ded33bf9c6fc0f3e37ec364a1cbbd25d68 CVE-2026-46388
MEDIUM
osquery: Unprivileged users can temporarily read file carve contents
Record summary
CVE-2026-46388 has a selected CVSS score of 4.4 (medium).
Description
osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. Prior to 5.23.1, an unprivileged attacker can read the contents of an osquery file carve until the carve completes and the temporary files are deleted because in-progress carve directories are not created with private permissions. If the carve targets a directory that the attacker controls, arbitrary file reads are possible, such as sensitive local files. This issue is fixed in version 5.23.1.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 10, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
osqueryBrowse osquery / osquery | CVE List | < 5.23.1 | affected |
References
4github.com
https://github.com/osquery/osquery/pull/8961 github.com
https://github.com/osquery/osquery/releases/tag/5.23.1 github.comConfirmation
https://github.com/osquery/osquery/security/advisories/GHSA-fg78-9q98-62hh