EIP-2026-102795

PRE-CVE

Calibre E-Book Reader - Local Privilege Escalation (2)

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-102795. PoCs published by zx2c4.

AI-analyzed exploit summary This exploit leverages a vulnerability in Calibre's mount helper to mount a crafted vfat filesystem over /etc, allowing an attacker to modify /etc/passwd and gain root access with the password 'toor'. It demonstrates a local privilege escalation (LPE) by abusing improper filesystem mounting permissions.

Description

Calibre E-Book Reader - Local Privilege Escalation (2)

Exploits (1)

exploitdb WORKING POC VERIFIED
by zx2c4 · bashlocallinux
https://www.exploit-db.com/exploits/18071

This exploit leverages a vulnerability in Calibre's mount helper to mount a crafted vfat filesystem over /etc, allowing an attacker to modify /etc/passwd and gain root access with the password 'toor'. It demonstrates a local privilege escalation (LPE) by abusing improper filesystem mounting permissions.

Classification
Working Poc 100%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: Calibre E-Book Reader (version unspecified, likely older versions)
No auth needed
Prerequisites: Local access to the system · Calibre installed with vulnerable mount helper · calibre-mount-helper executable accessible
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026