Description
A privilege escalation flaw was found in the scan_mysql actor of leapp-upgrade-el9toel10 (provided by leapp-repository). During RHEL 9 to RHEL 10 upgrades, the actor runs:
mysqld --validate-config --log-error-verbosity=2 directly as root in the Leapp actor context, bypassing the packaged MySQL systemd unit that normally starts the daemon as User=mysql.

A process compromised as the mysql OS identity can write a version-2 persisted configuration (mysqld-auto.cnf) and a malicious shared object into /var/lib/mysql (a directory owned by mysql). That persisted map can set plugin_dir to /var/lib/mysql and early_plugin_load (or related loader options such as plugin_load / plugin_load_add) so MySQL loads the attacker-controlled object during configuration validation. Plugin loading can reach dlopen() before MySQL’s runtime-user check and before plugin-symbol validation.

When an administrator subsequently runs the documented Leapp preupgrade or upgrade workflow, attacker-controlled code can execute as UID 0 with a full capability set in an unconfined SELinux domain (unconfined_t). The attack does not require write access to the default system plugin path under /usr; redirecting plugin_dir via mysql-owned persisted state is sufficient. Ordinary SQL privileges alone (including highly privileged SQL accounts) are not a sufficient startpoint — OS-level execution as the mysql service identity is required, plus later administrator invocation of Leapp.
Published: 2026-09-15
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation to root
Action: Patch Immediately
AI Analysis

Impact

During a RHEL 9 to RHEL 10 upgrade, the leapp‑upgrade‑el9toel10 scan_mysql actor executes mysqld --validate-config as the root user. An attacker who compromises the mysql OS identity can create a persisted configuration file and a malicious shared object in /var/lib/mysql, which is owned by the mysql user. By redirecting plugin_dir to /var/lib/mysql and specifying plugin_load options, MySQL loads the attacker’s object during configuration validation before its runtime user check and before plugin-symbol validation. This allows the attacker to execute arbitrary code with UID 0, full capabilities and in an unconfined SELinux domain, effectively achieving full system compromise. The vulnerability requires both an OS‑level compromise of the mysql service identity and the later execution of the Leapp upgrade workflow; ordinary SQL privileges alone are insufficient.

Affected Systems

Affected systems include Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 9.6 Extended Update Support, and Red Hat OpenStack Platform 17.1. Version information for the affected packages is not specified beyond the product line; users should ensure they are running the pre‑upgrade or upgrade packages referenced in the Red Hat errata RHSA‑2026:67608 and RHSA‑2026:67609.

Risk and Exploitability

The CVSS score of 7.3 indicates a high severity vulnerability. The EPSS score of less than 1 % suggests that, as of the latest data, exploitation is considered unlikely in the wild, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the attack requires only a compromised mysql service identity—an attainable target on systems with misconfigured or vulnerable MySQL installations—and the trigger is the normal Leapp upgrade process, which most administrators will run when updating their RHEL environment.

Generated by OpenCVE AI on September 16, 2026 at 06:07 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.


OpenCVE Recommended Actions

  • Install the latest leapp‑upgrade‑el9toel10 package provided in Red Hat errata RHSA‑2026:67608 or RHSA‑2026:67609 to eliminate the privileged mysqld execution path.
  • After the patch, verify that mysqld is no longer invoked as root during the preupgrade or upgrade workflow by reviewing the Leapp actor logs and ensuring no persisted configuration files in /var/lib/mysql are used to load plugins.
  • As a temporary precaution, reset any mysql‑owned mysqld‑auto.cnf files, change plugin_dir to a secure directory, and restrict write access to /var/lib/mysql to prevent future attacker‑controlled plugin loading before executing Leapp upgrades.

Generated by OpenCVE AI on September 16, 2026 at 06:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat rhel Eus
CPEs cpe:/o:redhat:enterprise_linux:9 cpe:/a:redhat:enterprise_linux:9::appstream
cpe:/a:redhat:rhel_eus:9.6::appstream
Vendors & Products Redhat rhel Eus
References

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Tue, 15 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Description A privilege escalation flaw was found in the scan_mysql actor of leapp-upgrade-el9toel10 (provided by leapp-repository). During RHEL 9 to RHEL 10 upgrades, the actor runs: mysqld --validate-config --log-error-verbosity=2 directly as root in the Leapp actor context, bypassing the packaged MySQL systemd unit that normally starts the daemon as User=mysql. A process compromised as the mysql OS identity can write a version-2 persisted configuration (mysqld-auto.cnf) and a malicious shared object into /var/lib/mysql (a directory owned by mysql). That persisted map can set plugin_dir to /var/lib/mysql and early_plugin_load (or related loader options such as plugin_load / plugin_load_add) so MySQL loads the attacker-controlled object during configuration validation. Plugin loading can reach dlopen() before MySQL’s runtime-user check and before plugin-symbol validation. When an administrator subsequently runs the documented Leapp preupgrade or upgrade workflow, attacker-controlled code can execute as UID 0 with a full capability set in an unconfined SELinux domain (unconfined_t). The attack does not require write access to the default system plugin path under /usr; redirecting plugin_dir via mysql-owned persisted state is sufficient. Ordinary SQL privileges alone (including highly privileged SQL accounts) are not a sufficient startpoint — OS-level execution as the mysql service identity is required, plus later administrator invocation of Leapp.
Title Leapp-repository: leapp-upgrade-el9toel10: leapp-upgrade-el9toel10: scan_mysql runs mysqld --validate-config as root and can load mysql-writable plugins
First Time appeared Redhat
Redhat enterprise Linux
Redhat openstack
Weaknesses CWE-250
CPEs cpe:/a:redhat:openstack:17.1
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
Redhat openstack
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Redhat Enterprise Linux Openstack Rhel Eus
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-15T16:12:49.945Z

Reserved: 2026-08-17T16:39:24.833Z

Link: CVE-2026-75092

cve-icon Vulnrichment

Updated: 2026-09-15T14:20:03.229Z

cve-icon NVD

Status : Received

Published: 2026-09-15T09:16:43.727

Modified: 2026-09-15T17:17:24.970

Link: CVE-2026-75092

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-15T00:00:00Z

Links: CVE-2026-75092 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T06:15:07Z

Weaknesses
  • CWE-250

    Execution with Unnecessary Privileges