← Vulnerability feed

Vulnerability record · CVE-2015-1867 · published 12 August 2015

CVE-2015-1867: Redhat enterprise linux high availability permissions and access controls vulnerability

Redhat · Enterprise Linux High Availability

Pacemaker before 1.1.13 does not properly evaluate added nodes, which allows remote read-only users to gain privileges via an acl command.

7.5 CVSS 2.0 High EPSS 3.0% · top 13.1% CWE-264 · Permissions and access controls
7.5CVSS 2.0 base score
3.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
18References
17 Jun 2026Last modified by NVD

Description

Pacemaker before 1.1.13 does not properly evaluate added nodes, which allows remote read-only users to gain privileges via an acl command.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2015-1867 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-2319Clusterlabs pcs vulnerabilityIt was discovered that an update for PCS package in RHBA-2023:2151 erratum released as part of Red Hat Enterprise Linux 9.2 failed to include the fix…EPSS 0.97%8.8CVE-2021-44142Samba vfs_fruit heap out-of-bounds read/write enables code executionSamba's vfs_fruit module mishandles extended file attributes (xattr), allowing out-of-bounds heap reads and writes when specially crafted EAs are pro…EPSS 73%analysed8.1CVE-2020-25717Samba improper input validation vulnerabilityA flaw was found in the way Samba maps domain users to local users. An authenticated attacker could use this flaw to cause possible privilege escalat…EPSS 1.6%7.8CVE-2018-16877Clusterlabs pacemaker improper authentication vulnerabilityA flaw was found in the way pacemaker's client-server authentication was implemented in versions up to and including 2.0.0. A local attacker could us…EPSS 0.39%7.8CVE-2016-7035Clusterlabs pacemaker improper authorization vulnerabilityAn authorization flaw was found in Pacemaker before 1.1.16, where it did not properly guard its IPC interface. An attacker with an unprivileged accou…EPSS 0.40%7.5CVE-2019-3885Clusterlabs pacemaker use after free vulnerabilityA use-after-free flaw was found in pacemaker up to and including version 2.0.1 which could result in certain sensitive information to be leaked via t…EPSS 2.0%7.5CVE-2016-7797Clusterlabs pacemaker vulnerabilityPacemaker before 1.1.15, when using pacemaker remote, might allow remote attackers to cause a denial of service (node disconnection) via an unauthent…EPSS 3.3%7.2CVE-2020-25654Clusterlabs pacemaker improper access control vulnerabilityAn ACL bypass flaw was found in pacemaker. An attacker having a local account on the cluster and in the haclient group could use IPC communication wi…EPSS 1.9%

Source: NIST National Vulnerability Database (record CVE-2015-1867), CISA KEV, FIRST EPSS (scores of 2026-10-01). This page is refreshed as NVD updates the record.