FreeBSD privilege escalation via CVE-2026-49413
A privilege escalation vulnerability in FreeBSD versions 14.x and 15.x allows attackers to elevate privileges on affected systems.
CERT-FR has issued an advisory regarding a privilege escalation vulnerability affecting multiple branches of FreeBSD operating systems. The flaw impacts FreeBSD versions 14 and 15 across various release branches, including production releases 14.3, 14.4, 15.0, and 15.1, as well as development branches.
The vulnerability, tracked as CVE-2026-49413, allows an attacker to elevate privileges on vulnerable FreeBSD systems. FreeBSD has released security advisory FreeBSD-SA-26:30 addressing this issue, with patches available for all affected branches. The advisory references fixes for specific build numbers across each affected branch.
Organizations running FreeBSD should consult the vendor's security advisory and apply patches immediately to mitigate the risk of privilege escalation attacks on their systems.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0716
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free