Database/Control plane, storage & DevOps
HTCondor (condor_schedd / Access Point): A user plants a specially crafted job that lies dormant, then runs as a
Impact
A user plants a specially crafted job that lies dormant, then runs as a different non-root user of the attacker's choosing once the Access Point is upgraded to an affected version. The upgrade itself is the trigger, which makes this an unusually nasty one to reason about - the exploit is armed before you install the vulnerable code.
Who can reach it
A user with WRITE access to the schedd, i.e. anyone allowed to submit jobs, on an AP running 24.7.3 or later.
What to do
Upgrade to HTCondor 24.12.14, 25.0.3 or 25.3.1. Before and after the upgrade, hunt for pre-planted jobs with: condor_q -all -constraint 'OsUser != Owner' and condor_rm anything suspicious. An AP already running a vulnerable version cannot have a new attack initiated against it, so the priority order is: scan the queue, then upgrade.
References
Related entries
- Sealed Secrets controller: unauthenticated template oracle recovers sealed secret plaintextCVE-2026-59341 · Bitnami Sealed Secrets controller (/v1/verify and /v1/rotate HTTP endpoints)Medium
- Apache Airflow 3.3.0-3.3.1: cookie wins over explicit bearer token, misattributing API calls and audit recordsCVE-2026-82355 · Apache Airflow core API (session cookie vs bearer token precedence)Medium
- Jenkins core: build CLI -s flag cancels other users' builds without the Item/Cancel permissionCVE-2026-84657 · Jenkins core (build CLI command, -s flag skips Item/Cancel check)Medium
- AMD IOMMU register interface - ASP coherency: Improper access control on the IOMMU register interface lets a privilegedCVE-2025-54509 · AMD IOMMU register interface - ASP coherencyMedium
- AGESA Boot Loader (ABL) - SPI ROM header input validation (AMD-SB-3003): The AGESA Boot Loader does not properlyCVE-2021-46772 · AGESA Boot Loader (ABL) - SPI ROM header input validation (AMD-SB-3003)Low
- Redis: Lua environment weakness lets a user inject code that runs with another Redis user's privilegesCVE-2022-24735 · RedisLow
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.