PT-2026-39145 · Akamai · Guardicore Platform Agent+1

Published

2026-05-08

·

Updated

2026-05-10

·

CVE-2026-34354

CVSS v3.1

7.4

High

VectorAV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Akamai Guardicore Platform Agent versions 7.0 through 7.3.1 Akamai Zero Trust Client versions 6.0 through 6.1.5 Akamai Guardicore Platform Agent (affected versions not specified)
Description Local privilege escalation is possible on Linux and macOS due to a Time-of-Check to Time-of-Use (TOCTOU) flaw. The GPA service creates an IPC socket in the world-writable /tmp directory and accepts unauthenticated IPC control messages. This allows an unprivileged local user to exploit the HandleSaveLogs() function by creating a log file and manipulating it into a symlink pointing to a targeted path, making arbitrary root-owned files world-writable. Additionally, the gimmelogs diagnostic collection tool, running with root privileges, is susceptible to command injection via the dbstore. On Windows, gimmelogs allows writing a ZIP archive to an unintended location.
Recommendations For Akamai Guardicore Platform Agent versions 7.0 through 7.3.1, update to a version later than 7.3.1. For Akamai Zero Trust Client versions 6.0 through 6.1.5, update to a version later than 6.1.5. As a temporary mitigation, restrict access to the /tmp directory or the gimmelogs tool to minimize the risk of exploitation.

Fix

LPE

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-34354

Affected Products

Guardicore Platform Agent
Zero Trust Client