CVE-2026-54001

Source
https://cve.org/CVERecord?id=CVE-2026-54001
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54001.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-54001
Aliases
  • GHSA-hr28-jvpx-68cx
Published
2026-07-10T14:49:18Z
Modified
2026-08-12T16:41:11Z
Severity
  • 7.0 (High) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
osquery: Heap buffer overflow via `authenticode` table (Windows)
Details

osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework. Prior to 5.23.1, on Windows, a local unprivileged attacker can cause a heap buffer out-of-bounds write if there is a query of the authenticode table targeting a maliciously crafted binary, due to publisher information parsing in getOriginalProgramName. If exploited successfully, this could allow a potential local privilege escalation from standard user to SYSTEM. This issue is fixed in version 5.23.1.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-122"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54001.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "fixed": "5.23.1"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/osquery/osquery

Affected ranges

Type
GIT
Repo
https://github.com/osquery/osquery
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": "REFERENCES"
}

Affected versions

0.*
0.0.2
1.*
1.0.2
1.0.3
1.0.4
1.0.5
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.8.0
1.8.1
1.8.2
2.*
2.0.0
2.1.0
2.1.1
2.1.2
2.10.0
2.10.1
2.10.2
2.10.3
2.10.4
2.11.0
2.11.1
2.11.2
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0
2.3.1
2.3.2
2.3.3
2.3.4
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0
2.6.1
2.7.0
2.8.0
2.8.1
2.9.0
2.9.1
2.9.2
3.*
3.0.0
3.1.0
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.2.6
3.2.7
3.2.8
3.2.9
3.3.0
3.3.1
3.3.2
4.*
4.0.0
4.0.1
4.0.2
4.1.0
4.1.1
4.1.2
4.2.0
4.3.0
4.4.0
4.5.0
4.5.1
4.6.0
4.7.0
4.8.0
4.9.0
5.*
5.0.0
5.0.1
5.1.0
5.10.0
5.10.1
5.10.2
5.11.0
5.12.0
5.12.1
5.13.0
5.13.1
5.14.0
5.14.1
5.15.0
5.16.0
5.17.0
5.18.0
5.19.0
5.2.0
5.2.1
5.2.2
5.20.0
5.21.0
5.22.0
5.22.1
5.23.0
5.3.0
5.4.0
5.5.0
5.5.1
5.6.0
5.7.0
5.8.0
5.8.1
5.8.2
5.9.0
5.9.1
v0.*
v0.0.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54001.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "283886038157249001085904951270182065068",
                "285873272593745641487616476674256273689",
                "138499954941120660949527084456780643227",
                "23400284557401938507561993011713184143",
                "180287355814760970901333659961095352739"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-54001-08767270",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/osquery/osquery/commit/59a808cda96d5a089cf6ec147efe152459284d54",
        "target": {
            "file": "tests/integration/tables/authenticode.cpp"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "237220395582663748917960012670782508566",
            "length": 108
        },
        "id": "CVE-2026-54001-64ead62c",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/osquery/osquery/commit/59a808cda96d5a089cf6ec147efe152459284d54",
        "target": {
            "file": "tests/integration/tables/authenticode.cpp",
            "function": "TEST_F"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "118683739597154858346068228729799647877",
            "length": 1184
        },
        "id": "CVE-2026-54001-9cc401be",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/osquery/osquery/commit/59a808cda96d5a089cf6ec147efe152459284d54",
        "target": {
            "file": "osquery/tables/system/windows/authenticode.cpp",
            "function": "getOriginalProgramName"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "123652659234302333876283263177204890259",
                "178775983326812485869585408728749357244",
                "208358014525042409148746933622351792677",
                "143275159745711910960043008628816811169",
                "265839029446489806182030292480903984331",
                "64342131187373583749493940121963538145",
                "313341974783317416158119323137563980158",
                "218614348098201550253491270365511480535",
                "40130054755274292906746795992936696424",
                "72211739438395677100613869155455943545",
                "79136154244196730329043813515680289956",
                "184076681608397273316045238945996621705",
                "55799888736442402196515809540253642164",
                "178040637249566550216340368184746358151",
                "74874625960100234340570681432504251067",
                "69244498338284723965107567650313591425",
                "334686492746056151081654360398532174192",
                "169261948339119312367306767682085841997",
                "257658083653612996960136022587464412332",
                "146767302623013860296348035460980498944",
                "267152507593443361323651565350511226008",
                "137226579793062214773144867186430769893",
                "161094030227436629289940526251488995854",
                "312262304852652255258814091507186117656",
                "150574127307128030955228309324355298009",
                "6347561236917925103147752961706612354",
                "61380374525772020355737143315826499191",
                "74874625960100234340570681432504251067",
                "69244498338284723965107567650313591425",
                "149414358778412747476886541465311037330",
                "257033988876825129680811194625687593320",
                "145915118280517480522362023870584038275",
                "252797944462312080472285132141228457250",
                "175432925302650715629917107983496099841",
                "304864215130903309527420008003072208389",
                "222250033818197274169401316921735522281",
                "158026541226986460768896770407331225459",
                "237927133398736812496393287882746860023"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-54001-b303b16a",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/osquery/osquery/commit/59a808cda96d5a089cf6ec147efe152459284d54",
        "target": {
            "file": "osquery/tables/system/windows/authenticode.cpp"
        }
    }
]
vanir_signatures_modified
"2026-08-12T16:41:11Z"