CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-50292

highCVSS 7.4covered by 3 sourcesfirst seen 2026-06-09
It was discovered that libinput did not properly escape device properties. A local attacker could possibly use this issue to inject arbitrary udev properties and execute arbitrary code as root.

CSIRTS triage

What
The vulnerability allows a local attacker to inject arbitrary udev properties and execute arbitrary code as root.
Who is affected
Local attackers on systems using libinput are affected.
Urgency
Remediation is urgent due to the potential for arbitrary code execution with root privileges.
Action
Apply patches or updates to libinput to resolve the vulnerability.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-50292

Get an email if CVE-2026-50292 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (3)

External references

NVD record for CVE-2026-50292

CVE.org record

Embed the live status

CVE-2026-50292 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-50292 status](https://www.csirts.com/badge/CVE-2026-50292)](https://www.csirts.com/cve/CVE-2026-50292)