EIP-2026-102794
PRE-CVECalibre E-Book Reader - Local Privilege Escalation (1)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-102794. PoCs published by zx2c4.
AI-analyzed exploit summary This exploit leverages a SUID mount helper in Calibre that uses execlp to execute 'mount', allowing PATH manipulation to execute a malicious 'mount' script as root. The script creates a temporary directory, writes a malicious 'mount' executable, and overrides PATH to gain root privileges.
Description
Calibre E-Book Reader - Local Privilege Escalation (1)
Exploits (1)
This exploit leverages a SUID mount helper in Calibre that uses execlp to execute 'mount', allowing PATH manipulation to execute a malicious 'mount' script as root. The script creates a temporary directory, writes a malicious 'mount' executable, and overrides PATH to gain root privileges.