Insufficiently protected credentials in cURL - CVE-2026-8926

 

Insufficiently protected credentials in cURL - CVE-2026-8926

Published: June 24, 2026


Vulnerability identifier: #VU135084
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-8926
CWE-ID: CWE-522
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to use credentials intended for another user.

The vulnerability exists due to insufficiently protected credentials in .netrc credential handling when processing a URL that specifies a username without a password. A remote user can supply a URL with a username that has no matching .netrc entry to use credentials intended for another user.

This issue occurs only when curl is configured to use a .netrc file and the target host has credentials stored for a different user.


Affected software

cURL
SUSE Linux Enterprise Server 15 SP6
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Micro for Rancher
SUSE Linux Enterprise Micro
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Ubuntu
Basesystem Module
openSUSE Leap
openEuler
Fedora
LANTIME Operating System Firmware (LTOS)
curl (Ubuntu package)
curl-help
libcurl-devel
libcurl
curl-debugsource
curl-debuginfo
curl
curl (Red Hat package)
libcurl-devel-64bit
libcurl4-64bit
libcurl4
libcurl4-debuginfo
libcurl4-32bit
libcurl-devel-32bit
libcurl4-32bit-debuginfo
libcurl-mini4-debuginfo
curl-mini-debugsource
curl-fish-completion
curl-zsh-completion
libcurl-devel-doc
libcurl4-64bit-debuginfo
libcurl-mini4

How to mitigate CVE-2026-8926

Install security update from vendor's website.

cURL - update to 8.21.0
LANTIME Operating System Firmware (LTOS) - update to 7.10.013
curl (Ubuntu package) - addressed in versions 7.35.0-1ubuntu2.20+esm20, 7.35.0-1ubuntu2.20+esm23, 7.47.0-1ubuntu2.19+esm16, 7.58.0-2ubuntu3.24+esm9, 7.68.0-1ubuntu2.25+esm4, 7.81.0-1ubuntu1.25, 8.5.0-2ubuntu10.10, 8.14.1-2ubuntu1.4, 8.18.0-1ubuntu2.2
curl-help - addressed in versions 7.71.1-52, 7.79.1-53, 8.4.0-33, 8.4.0-35
libcurl-devel - addressed in versions 7.71.1-52, 7.79.1-53, 8.4.0-33, 8.4.0-35
libcurl - addressed in versions 7.71.1-52, 7.79.1-53, 8.4.0-33, 8.4.0-35
curl-debugsource - addressed in versions 7.71.1-52, 7.79.1-53, 8.4.0-33, 8.4.0-35
curl-debuginfo - addressed in versions 7.71.1-52, 7.79.1-53, 8.4.0-33, 8.4.0-35
curl - addressed in versions 7.71.1-52, 7.79.1-53, 8.4.0-33, 8.4.0-35
curl (Red Hat package) - update to 8.12.1-1.el10_0.10
libcurl-devel-64bit - addressed in versions 8.14.1-150400.5.91.1, 8.14.1-150600.4.51.1
libcurl4-64bit - addressed in versions 8.14.1-150400.5.91.1, 8.14.1-150600.4.51.1
curl-debuginfo - addressed in versions 8.14.1-150400.5.91.1, 8.14.1-150600.4.51.1, 8.14.1-150700.7.23.1
curl-debugsource - addressed in versions 8.14.1-150400.5.91.1, 8.14.1-150600.4.51.1, 8.14.1-150700.7.23.1
libcurl4 - addressed in versions 8.14.1-150400.5.91.1, 8.14.1-150600.4.51.1, 8.14.1-150700.7.23.1
curl - addressed in versions 8.14.1-150400.5.91.1, 8.14.1-150600.4.51.1, 8.14.1-150700.7.23.1
libcurl4-debuginfo - addressed in versions 8.14.1-150400.5.91.1, 8.14.1-150600.4.51.1, 8.14.1-150700.7.23.1
libcurl4-32bit - addressed in versions 8.14.1-150400.5.91.1, 8.14.1-150600.4.51.1, 8.14.1-150700.7.23.1
libcurl-devel-32bit - addressed in versions 8.14.1-150400.5.91.1, 8.14.1-150600.4.51.1
libcurl4-32bit-debuginfo - addressed in versions 8.14.1-150400.5.91.1, 8.14.1-150600.4.51.1, 8.14.1-150700.7.23.1
libcurl-mini4-debuginfo - addressed in versions 8.14.1-150400.5.91.1, 8.14.1-150600.4.51.1
curl-mini-debugsource - addressed in versions 8.14.1-150400.5.91.1, 8.14.1-150600.4.51.1
libcurl-devel - addressed in versions 8.14.1-150400.5.91.1, 8.14.1-150600.4.51.1, 8.14.1-150700.7.23.1
curl-fish-completion - addressed in versions 8.14.1-150400.5.91.1, 8.14.1-150600.4.51.1
curl-zsh-completion - addressed in versions 8.14.1-150400.5.91.1, 8.14.1-150600.4.51.1
libcurl-devel-doc - addressed in versions 8.14.1-150400.5.91.1, 8.14.1-150600.4.51.1
libcurl4-64bit-debuginfo - addressed in versions 8.14.1-150400.5.91.1, 8.14.1-150600.4.51.1
libcurl-mini4 - addressed in versions 8.14.1-150400.5.91.1, 8.14.1-150600.4.51.1
curl - addressed in versions 8.15.0-8.fc43, 8.18.0-8.fc44

External References

Related Security Bulletins