Junglewise Threat Intelligence

CVE-2026-68491: SolusVM arbitrary file overwrite via symlink

CVE-2026-68491 · Severity: info · Published 2026-09-15

Executive brief

SolusVM is a virtualization management platform used by hosting providers to manage virtual private servers. A symlink race condition in the product could allow an attacker to overwrite arbitrary files on the system, potentially compromising the integrity of the management system and affecting all hosted customers.

Technical details

The vulnerability is a symlink race condition caused by insufficient checks when handling file operations. An attacker can leverage this to create or exploit a symbolic link to cause the application to overwrite arbitrary files on the system. The attack vector is local, requiring filesystem access to the affected system. This is a classic time-of-check-time-of-use (TOCTOU) vulnerability in file handling code. Fixes were applied in security hardening releases (versions 1.30.13, 1.30.14, and 1.30.15 published between August and September 2026).

Affected products

  • SolusVM SolusVM before 1.30.13

Timeline

  • 2026-09-15: disclosed
  • 2026-08-20: patched: Version 1.30.13 included security improvements
  • 2026-09-03: patched: Version 1.30.14 included security hardening
  • 2026-09-15: patched: Version 1.30.15 included security hardening

References