Description
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, a malicious rule could potentially overwrite any file on the file system on rule load or reload. Versions 7.0.16 and 8.0.5 fix the issue. Some workarounds are available. Preprocess `load`+ `save` rules to disallow absolute filenames for save, use Suricata's privilege dropping to limit writable files, and/or configure landlock in suricata.yaml.
Published: 2026-09-10
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary File Write
Action: Apply Patch
AI Analysis

Impact

The vulnerability allows a malicious Suricata rule to overwrite any file on the system when the rule is loaded or reloaded. It stems from improper handling of filenames in the "save" directive, resulting in an arbitrary file write that could compromise system data or configuration.

Affected Systems

Suricata installations older than version 7.0.16 on the 7.x branch or older than 8.0.5 on the 8.x branch are affected. These releases are distributed by OISF and are commonly employed in IDS/IPS environments that use custom or third‑party rule sets.

Risk and Exploitability

The CVSS score of 4.4 indicates moderate severity. The EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation has been reported. Exploitation requires the attacker to be able to load a crafted rule, which triggers the arbitrary write. Workarounds are available by sanitizing rule files, limiting Suricata’s write permissions, and applying the recommended configuration changes.

Generated by OpenCVE AI on September 21, 2026 at 05:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Suricata to version 7.0.16 or later (or 8.0.5 or newer) to apply the official fix.
  • Preprocess load and save rule files to ensure that any "save" command uses only relative filenames and disallows absolute paths.
  • Configure Suricata to run with the lowest effective privileges and optionally enable landlock in suricata.yaml to further restrict file system access.

Generated by OpenCVE AI on September 21, 2026 at 05:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-73
References
Metrics threat_severity

None

threat_severity

Moderate


Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:oisf:suricata:*:*:*:*:*:*:*:*

Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
First Time appeared Oisf
Oisf suricata
Vendors & Products Oisf
Oisf suricata

Thu, 10 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Description Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, a malicious rule could potentially overwrite any file on the file system on rule load or reload. Versions 7.0.16 and 8.0.5 fix the issue. Some workarounds are available. Preprocess `load`+ `save` rules to disallow absolute filenames for save, use Suricata's privilege dropping to limit writable files, and/or configure landlock in suricata.yaml.
Title Suricata datasets: save to absolute filename can be bypassed when combined with load command
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T15:06:41.846Z

Reserved: 2026-05-13T07:45:21.250Z

Link: CVE-2026-45767

cve-icon Vulnrichment

Updated: 2026-09-15T15:06:38.010Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-10T22:16:56.683

Modified: 2026-09-16T20:18:43.117

Link: CVE-2026-45767

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-10T21:31:02Z

Links: CVE-2026-45767 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T05:15:09Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

  • CWE-73

    External Control of File Name or Path