Executive brief
Akamai Guardicore Platform Agent and Zero Trust Client, which are security tools used to manage network access and microsegmentation, contain vulnerabilities that allow a local user to gain administrative (root) privileges. By exploiting how the software handles log files and diagnostic tools, an attacker who already has limited access to a Linux or macOS system can take full control of the machine. This could lead to unauthorized data access, disabling of security controls, or further movement within the corporate network.
Technical details
The Akamai Guardicore Platform Agent (GPA) service on Linux and macOS creates an IPC socket in the world-writable /tmp directory and accepts unauthenticated control messages. A Time-of-Check Time-of-Use (TOCTOU) vulnerability exists in the HandleSaveLogs() function; an attacker can send a message to create a log file and then replace that file with a symbolic link to a sensitive system file, causing the service to make that target file world-writable. Additionally, the 'gimmelogs' diagnostic tool, which runs with root privileges, is vulnerable to command injection via the dbstore. On Windows, the 'gimmelogs' tool is also affected by an arbitrary file write vulnerability involving ZIP archives. These flaws allow a local unprivileged user to escalate privileges to root or SYSTEM.
Affected products
- Akamai Guardicore Platform Agent (GPA) 7.0 through 7.3.1
- Akamai Zero Trust Client 6.0 through 6.1.5
Timeline
- 2026-05-08: disclosed
- 2026-05-08: advisory