Improper Access Control in Node.js - CVE-2026-21711
Published: March 25, 2026
Vulnerability details
The vulnerability allows a local user to bypass permission restrictions.
The vulnerability exists due to improper access control in Unix Domain Socket (UDS) server operations in the Node.js Permission Model when binding or listening on UDS endpoints. A local user can run code with --permission but without --allow-net to create and expose local IPC endpoints, bypassing intended network restrictions.
This issue affects only environments using the experimental Permission Model with --allow-net intentionally omitted.
Affected software
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
nodejs24 (Red Hat package)
How to mitigate CVE-2026-21711
nodejs24 (Red Hat package) - update to 24.14.1-2.el10_1