EIP-2026-102773

PRE-CVE

Altair Engineering PBS Pro 10.x - 'pbs_mom' Insecure Temporary File Creation

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-102773. PoCs published by Bartlomiej Balcerek.

AI-analyzed exploit summary This exploit demonstrates a symbolic-link race condition vulnerability in Altair Engineering PBS Pro < 10.4, allowing local attackers to overwrite arbitrary files via insecure temporary file handling. The PoC compiles a C program to repeatedly create symlinks, targeting PBS Pro's spool directory to achieve file corruption or denial of service.

Description

Altair Engineering PBS Pro 10.x - 'pbs_mom' Insecure Temporary File Creation

Exploits (1)

exploitdb WORKING POC VERIFIED
by Bartlomiej Balcerek · bashlocallinux
https://www.exploit-db.com/exploits/34267

This exploit demonstrates a symbolic-link race condition vulnerability in Altair Engineering PBS Pro < 10.4, allowing local attackers to overwrite arbitrary files via insecure temporary file handling. The PoC compiles a C program to repeatedly create symlinks, targeting PBS Pro's spool directory to achieve file corruption or denial of service.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Moderate
Reliability
Racy
Target: Altair Engineering PBS Pro < 10.4
Auth required
Prerequisites: Local access to the submitting host · Ability to submit jobs via PBS Pro · GCC installed for compilation · SSH access to execution host
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026