#VU122809 Out-of-bounds write in MUNGE - CVE-2026-25506
Published: February 13, 2026
MUNGE
Dun
Description
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to a boundary error. A local user can trigger an out-of-bounds write in the authentication daemon and force it to leak cryptographic key material from the process memory. The extracted information can be used to forge arbitrary MUNGE credentials to impersonate any user (including root) to services that rely on MUNGE for authentication.