Insufficiently protected credentials in cURL - CVE-2026-8926
Published: June 24, 2026
Vulnerability details
The vulnerability allows a remote user to use credentials intended for another user.
The vulnerability exists due to insufficiently protected credentials in .netrc credential handling when processing a URL that specifies a username without a password. A remote user can supply a URL with a username that has no matching .netrc entry to use credentials intended for another user.
This issue occurs only when curl is configured to use a .netrc file and the target host has credentials stored for a different user.
Affected software
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Micro for Rancher
SUSE Linux Enterprise Micro
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Ubuntu
Basesystem Module
openSUSE Leap
openEuler
Fedora
LANTIME Operating System Firmware (LTOS)
curl (Ubuntu package)
curl-help
libcurl-devel
libcurl
curl-debugsource
curl-debuginfo
curl
curl (Red Hat package)
libcurl-devel-64bit
libcurl4-64bit
libcurl4
libcurl4-debuginfo
libcurl4-32bit
libcurl-devel-32bit
libcurl4-32bit-debuginfo
libcurl-mini4-debuginfo
curl-mini-debugsource
curl-fish-completion
curl-zsh-completion
libcurl-devel-doc
libcurl4-64bit-debuginfo
libcurl-mini4
How to mitigate CVE-2026-8926
LANTIME Operating System Firmware (LTOS) - update to 7.10.013
curl (Ubuntu package) - addressed in versions 7.35.0-1ubuntu2.20+esm20, 7.35.0-1ubuntu2.20+esm23, 7.47.0-1ubuntu2.19+esm16, 7.58.0-2ubuntu3.24+esm9, 7.68.0-1ubuntu2.25+esm4, 7.81.0-1ubuntu1.25, 8.5.0-2ubuntu10.10, 8.14.1-2ubuntu1.4, 8.18.0-1ubuntu2.2
curl-help - addressed in versions 7.71.1-52, 7.79.1-53, 8.4.0-33, 8.4.0-35
libcurl-devel - addressed in versions 7.71.1-52, 7.79.1-53, 8.4.0-33, 8.4.0-35
libcurl - addressed in versions 7.71.1-52, 7.79.1-53, 8.4.0-33, 8.4.0-35
curl-debugsource - addressed in versions 7.71.1-52, 7.79.1-53, 8.4.0-33, 8.4.0-35
curl-debuginfo - addressed in versions 7.71.1-52, 7.79.1-53, 8.4.0-33, 8.4.0-35
curl - addressed in versions 7.71.1-52, 7.79.1-53, 8.4.0-33, 8.4.0-35
curl (Red Hat package) - update to 8.12.1-1.el10_0.10
libcurl-devel-64bit - addressed in versions 8.14.1-150400.5.91.1, 8.14.1-150600.4.51.1
libcurl4-64bit - addressed in versions 8.14.1-150400.5.91.1, 8.14.1-150600.4.51.1
curl-debuginfo - addressed in versions 8.14.1-150400.5.91.1, 8.14.1-150600.4.51.1, 8.14.1-150700.7.23.1
curl-debugsource - addressed in versions 8.14.1-150400.5.91.1, 8.14.1-150600.4.51.1, 8.14.1-150700.7.23.1
libcurl4 - addressed in versions 8.14.1-150400.5.91.1, 8.14.1-150600.4.51.1, 8.14.1-150700.7.23.1
curl - addressed in versions 8.14.1-150400.5.91.1, 8.14.1-150600.4.51.1, 8.14.1-150700.7.23.1
libcurl4-debuginfo - addressed in versions 8.14.1-150400.5.91.1, 8.14.1-150600.4.51.1, 8.14.1-150700.7.23.1
libcurl4-32bit - addressed in versions 8.14.1-150400.5.91.1, 8.14.1-150600.4.51.1, 8.14.1-150700.7.23.1
libcurl-devel-32bit - addressed in versions 8.14.1-150400.5.91.1, 8.14.1-150600.4.51.1
libcurl4-32bit-debuginfo - addressed in versions 8.14.1-150400.5.91.1, 8.14.1-150600.4.51.1, 8.14.1-150700.7.23.1
libcurl-mini4-debuginfo - addressed in versions 8.14.1-150400.5.91.1, 8.14.1-150600.4.51.1
curl-mini-debugsource - addressed in versions 8.14.1-150400.5.91.1, 8.14.1-150600.4.51.1
libcurl-devel - addressed in versions 8.14.1-150400.5.91.1, 8.14.1-150600.4.51.1, 8.14.1-150700.7.23.1
curl-fish-completion - addressed in versions 8.14.1-150400.5.91.1, 8.14.1-150600.4.51.1
curl-zsh-completion - addressed in versions 8.14.1-150400.5.91.1, 8.14.1-150600.4.51.1
libcurl-devel-doc - addressed in versions 8.14.1-150400.5.91.1, 8.14.1-150600.4.51.1
libcurl4-64bit-debuginfo - addressed in versions 8.14.1-150400.5.91.1, 8.14.1-150600.4.51.1
libcurl-mini4 - addressed in versions 8.14.1-150400.5.91.1, 8.14.1-150600.4.51.1
curl - addressed in versions 8.15.0-8.fc43, 8.18.0-8.fc44
External References
Related Security Bulletins
- Multiple vulnerabilities in cURL
- Ubuntu update for curl
- openEuler 24.03 LTS SP3 update for curl
- openEuler 24.03 LTS SP1 update for curl
- openEuler 24.03 LTS SP4 update for curl
- Fedora 44 update for curl
- Fedora 43 update for curl
- Multiple vulnerabilities in Meinberg LANTIME firmware
- SUSE update for curl
- SUSE update for curl
- openEuler 24.03 LTS SP3 update for curl
- openEuler 24.03 LTS SP1 update for curl
- openEuler 22.03 LTS SP4 update for curl
- openEuler 20.03 LTS SP4 update for curl
- SUSE update for curl
- openEuler 24.03 LTS SP4 update for curl
- Red Hat Enterprise Linux 10 update for curl
- Ubuntu update for curl