Nix, Privilege Escalation via Symlink Following, CVE-2026-39860 (Critical) -DC-Oct2026-2896

Listen to this Post

The vulnerability identified as CVE-2026-39860 stems from an improper handling of symbolic links during fixed-output derivation output registration within the Nix daemon architecture.
In multi-user installations or default configurations on NixOS systems, unprivileged local users are permitted to submit builds and interact directly with the daemon process.
During the output registration phase, the daemon processes files generated within a sandboxed environment and registers them into the global shared Nix store.
Due to insufficient validation checks introduced as a regression from previous patches addressing related path traversal issues, a race condition and symlink-following flaw can be actively triggered.
Specifically, a malicious local user can manipulate symbolic links inside a crafted fixed-output derivation to point to sensitive system files residing outside the intended store path.
When the Nix daemon processes the output registration, it blindly follows these symbolic links with elevated daemon privileges running as root.
This dangerous behavior allows the daemon process to overwrite arbitrary files on the host filesystem that are writable by the process orchestrating the builds.
Consequently, local unprivileged attackers can leverage this exact capability to overwrite critical system binaries, configuration files, or library paths.
Upon subsequent system execution or security checks, these modified files lead to immediate local privilege escalation, granting the attacker full root control.
The flaw successfully bypasses standard sandboxing boundaries because the output registration phase occurs outside the strict isolation sandbox context, trusting path resolutions improperly.
Mitigation requires updating the core package manager binaries to incorporate strict boundary verifications and disable unsafe symlink traversal during output registration stages.

DailyCVE Form:

Platform: Nix daemon
Version: Pre 2.34.5
Vulnerability: Privilege escalation
Severity: Critical risk
date: April 2026

Prediction: Released today

What Undercode Say:

Analytics

Analysis of CVE-2026-39860 reveals a severe local exploitation risk for multi-user Linux environments where untrusted users are permitted to submit builds. The attack vector requires local access with low attack complexity, granting high impact across confidentiality, integrity, and system availability.
Showing bash commands and codes related to the blog

nix-daemon --version
nix-build --expr 'derivation { name = "exploit"; builder = "/bin/sh"; system = "x86_64-linux"; }'
tail -n 50 /var/log/nix/nix-daemon.log

How Exploit: (Educational Purposes!)

An attacker prepares a malicious fixed-output derivation containing a symbolic link pointing to a sensitive target file such as /etc/sudoers. By triggering the build and exploiting the race condition during output registration, the privileged Nix daemon overwrites the target file with attacker-controlled data, entirely bypassing sandbox restrictions.

Protection: from this CVE

Upgrade the Nix package manager immediately to version 2.34.5, 2.33.4, 2.32.7, 2.31.4, 2.30.4, 2.29.3, 2.28.6, or later. Additionally, restrict build access using the `allowed-users` configuration setting to trusted users only.

Impact:

Complete system compromise and unauthorized root privilege escalation on multi-user Nix installations and standard NixOS systems.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top