Junglewise Threat Intelligence

CVE-2026-63404: Faktory insecure temporary file privilege escalation

CVE-2026-63404 · Severity: info · Published 2026-08-25

Executive brief

Faktory is a background job server that uses an embedded Redis database for storing job queues. Versions before 1.10.0 write the Redis configuration to a world-writable temporary location with a predictable name, allowing any local user to pre-plant a malicious configuration. An attacker can exploit this to expose the job queue over an unauthenticated network port, steal job data, or execute arbitrary code with root privileges since Faktory typically runs as root.

Technical details

The vulnerability is a time-of-check-time-of-use (TOCTOU) race condition combined with insecure temporary file handling in the embedded Redis bootstrapper. Faktory writes its Redis startup configuration to the fixed, world-writable path `/tmp/redis.conf`, creating it only if it does not already exist and never validating its contents on subsequent boots. A local unprivileged attacker can pre-create `/tmp/redis.conf` with arbitrary Redis directives (such as bind, protected-mode, requirepass, and loadmodule) before Faktory starts. Faktory only overrides three options (unixsocket, dir, logfile), leaving attacker-controlled directives intact. The loadmodule directive enables arbitrary native code execution in the root-owned Redis process, allowing privilege escalation from local unprivileged user to root. This issue is fixed in version 1.10.0.

Affected products

  • Kontribsys Faktory prior to 1.10.0

Timeline

  • 2026-08-25: disclosed
  • 2026-08-10: patched: Version 1.10.0 released

References