CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-40556: Insecure Directory Permissions in GNU nano Leading to Privilege Abuse

unknownCVE-2026-40556

CSIRTS triage

What
Insecure directory permissions in GNU nano allow privilege abuse.
Who is affected
Installations of GNU nano with the vulnerable directory permission configuration are affected.
Urgency
Remediation timing depends on deployment context; severity is unknown and requires investigation of exposure.
Action
Upgrade GNU nano to a patched version with corrected directory permissions or manually fix permissions on affected installations.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch nano

Get an email when a new nano advisory drops — max one per day, one-click unsubscribe.

Details

Source
Microsoft Security Response Center (INTL · vendor-psirt · site)
Severity
unknown
Published
2026-08-06
Exploitation
Not in CISA KEV at last sync

Original advisory: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40556

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-40556coverage & exploitation statusNVD · CVE.org

More from Microsoft Security Response Center