osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. Prior to 5.23.1, on Windows, a local unprivileged attacker can cause a heap buffer out-of-bounds write if there is a query of the processes table targeting a maliciously crafted process, due to unchecked PEB string lengths in process command-line and current-directory reads. If exploited successfully, this could allow a potential local privilege escalation from standard user to SYSTEM. This issue is fixed in version 5.23.1.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-122"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54000.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"fixed": "5.23.1"
}
],
"source": "AFFECTED_FIELD"
}
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54000.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "228852708779820532786320834819503120482",
"length": 636
},
"id": "CVE-2026-54000-87e361a3",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/osquery/osquery/commit/3d457c412eb0c986b0c37d8903edae8bc9f9e246",
"target": {
"file": "osquery/tables/system/windows/processes.cpp",
"function": "getProcessCommandLineLegacy"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "306587940601306112580030435210540487004",
"length": 742
},
"id": "CVE-2026-54000-f7669778",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/osquery/osquery/commit/3d457c412eb0c986b0c37d8903edae8bc9f9e246",
"target": {
"file": "osquery/tables/system/windows/processes.cpp",
"function": "getProcessPathInfo"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"308447981142363211615985515753655096694",
"232315947104041886406316091090938485175",
"314634592002000634925898458983674878137",
"92311105500033901178883336836487023411",
"208063912228706891450281498564227138390",
"66651716933959046862944774162173267595",
"89234578315553828212101138330780584999",
"122262961232880432737998836488539864145",
"6895062439527825342753533470593808033",
"315361247399661697776431929753831436842",
"141000154865052482740855173439526373716",
"41198519730047945622789183238386735324",
"132053531584013751190090919823165591976",
"220151174551386121323712572495857980154",
"270905240626256297592521923558568990732",
"255587809683293760045875561171589651239",
"46881228201026150625723437457918000793",
"247197467486218324662455351189874724308",
"76490202239689777896791425933957117020",
"324665787407035585325812862623802451242",
"82961630910669690687645073568577066436",
"244188182522411499524449215540225028559",
"135041797057326685469714268945066859245",
"22836615563871611569220703371470858316",
"194080028447130102827395124653681757956",
"281401315621537078489076989095945051706",
"336707167467513026736948309981130714434",
"83337693850768541698276919012131404938",
"309799315633791389833559431059065988193",
"317408809212888510464491819030866407568",
"260076543256415130708597004250377412531",
"8337832815307951409042840575845075265",
"220209825340345263745630311540945157114",
"199511249804544759600499031721147892449",
"131876094478714020836757363604760200899"
],
"threshold": 0.9
},
"id": "CVE-2026-54000-f7c21e83",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/osquery/osquery/commit/3d457c412eb0c986b0c37d8903edae8bc9f9e246",
"target": {
"file": "osquery/tables/system/windows/processes.cpp"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "78336634327868810944208183988722797997",
"length": 667
},
"id": "CVE-2026-54000-fcbbc7f1",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/osquery/osquery/commit/3d457c412eb0c986b0c37d8903edae8bc9f9e246",
"target": {
"file": "osquery/tables/system/windows/processes.cpp",
"function": "getProcessCurrentDirectory"
}
}
]
"2026-08-12T16:41:10Z"