Description
An insufficient check allowed for the overwrite of arbitrary files via a symlink.
Published: 2026-09-15
Score: 9.4 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Guest‑to‑Host Privilege Escalation via arbitrary file overwrite
Action: Immediate Patch
AI Analysis

Impact

An insufficient check allows overwriting arbitrary files through a symlink, enabling a guest user to overwrite host‑side files and elevate privileges. The flaw can lead to full host compromise and is classified as CWE‑59. This provides attackers the ability to modify system configuration or binaries, compromising confidentiality, integrity, and availability.

Affected Systems

The vulnerability affects Webpros SolusVM; no specific version range is disclosed, so all current installations are considered vulnerable until patched.

Risk and Exploitability

The CVSS score is 9.4, indicating critical severity. The EPSS score is in the < 1% range, suggesting a low probability of exploitation, and it is not listed in the CISA KEV catalog. Likely the attack requires guest access to a directory that the host monitors for symlink resolution, whereby a crafted symlink can point to a privileged file; the exploiter then overwrites it, achieving host‑level access. This path is not externally exposed but can be leveraged if the host allows symlinks from guest paths.

Generated by OpenCVE AI on September 18, 2026 at 14:11 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update SolusVM to the latest release that fixes the symlink overwrite flaw (see the 1.30.15 release notes).
  • Reconfigure host‑controlled directories to deny write permissions for guest users on files that may be targeted by symlinks.
  • Enable filesystem monitoring or audit logging to detect and alert on unexpected file overwrites or symlink creations.

Generated by OpenCVE AI on September 18, 2026 at 14:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Title SolusVM Arbitrary File Overwrite via Symlink Leading to Guest‑to‑Host Privilege Escalation

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Webpros
Webpros solusvm
Vendors & Products Webpros
Webpros solusvm

Wed, 16 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
Title SolusVM Arbitrary File Overwrite via Symlink Leading to Guest‑to‑Host Privilege Escalation

Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
Description An insufficient check allowed for the overwrite of arbitrary files via a symlink.
Weaknesses CWE-59
References
Metrics cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2026-09-16T18:04:11.685Z

Reserved: 2026-07-30T15:00:00.609Z

Link: CVE-2026-68491

cve-icon Vulnrichment

Updated: 2026-09-16T18:04:06.860Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T21:16:42.423

Modified: 2026-09-18T19:41:42.593

Link: CVE-2026-68491

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T14:15:09Z

Weaknesses
  • CWE-59

    Improper Link Resolution Before File Access ('Link Following')