All incidents

CISA adds Red Hat ABRT privilege escalation flaw (CVE-2015-5287) to KEV catalogue

incidentopenAug 26, 2026 — Aug 27, 2026

CISA has added CVE‑2015‑5287 to its Known Exploited Vulnerabilities catalogue, warning that the flaw in Red Hat’s Automatic Bug Reporting Tool is being actively exploited. The vulnerability lets a local user raise privileges to root by exploiting a symlink weakness in ABRT. Systems still running older, unsupported releases are most at risk.

CVE‑2015‑5287 carries a CVSS v3 score of 7.8, rated HIGH. The fault lies in how ABRT creates temporary files with predictable names; an attacker who can write to the same directory can replace the expected file with a symlink pointing to a sensitive target. When ABRT follows the link it inherits elevated permissions, allowing arbitrary code execution with root privileges.

Red Hat Enterprise Linux versions that include the ABRT service are affected, specifically those prior to the patch issued in RHSA‑2015‑2505. A fix is available through that advisory, but systems that have reached end‑of‑life no longer receive updates and remain vulnerable unless the tool is removed or disabled.

Although CISA has not linked the flaw to any particular threat group, its inclusion in the KEV catalogue indicates that the vulnerability is seen in the wild. Organisations that retain legacy Linux servers for compatibility or hardware reasons should treat the finding as a prompt to review their exposure.

First, identify all hosts running ABRT and verify the installed version against the patched release. Where possible, apply the update from Red Hat’s advisory RHSA‑2015‑2505 immediately. If patching cannot be done, consider disabling the ABRT service or tightening permissions on the temporary directory it uses.

Next, enforce least‑privilege principles for local accounts and monitor for unusual symlink creation in /var/tmp or /tmp directories. Prioritise remediation in line with CISA’s KEV guidance, and maintain an asset inventory to ensure no forgotten system slips through the cracks.

Administrators should also check audit logs for unexpected changes to file ownership or execution of privileged processes after a crash report is generated. Where ABRT remains necessary, consider implementing file integrity monitoring on the directories it uses to detect illicit symlink creation in real time. Regularly reviewing these alerts helps catch attempts before they succeed.

Intelligence briefing updated Aug 27, 2026

CVE-2015-5287 7.8 KEV
Root sourcenvd.nist.gov
Timeline Coverage

Swipe to explore timeline