CVE-2015-5287 carries a CVSS 3.1 base score of 7.8 against Red Hat’s Automatic Bug Reporting Tool (ABRT). NVD classifies it as CWE-59 (Improper Link Resolution Before File Access). CISA added this CVE to its Known Exploited Vulnerabilities catalog on August 26, 2026 — confirming exploitation directly through CISA’s own listing process, more than a decade after this vulnerability was originally disclosed in December 2015.
Because CISA KEV itself is the authoritative source for exploitation status, this CVE carries high confidence on that point. CISA KEV listing also means the Binding Operational Directive 26-04 remediation obligation applies to in-scope federal agencies, per CISA’s own mitigation guidance in our source data.
What the flaw is
NVD’s description states the abrt-hook-ccpp helper program in ABRT before version 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack against a file with a predictable name, citing /var/tmp/abrt/abrt-hax-coredump and /var/spool/abrt/abrt-hax-coredump as examples. NVD’s CVSS vector marks this local (AV:L) and requiring low privileges (PR:L), consistent with a local privilege-escalation profile exploitable by a user who already holds some level of access to the affected system.
Evidence and confidence
- High confidence — exploitation status, sourced directly from CISA KEV, which our evidence model treats as an authoritative single source for this specific field.
- Medium confidence — the CVSS 7.8 score, the vector (
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), and the CWE-59 classification, which trace to NVD alone in our current ingestion, corroborated by Red Hat’s own linked fix commit and errata. - Very high exploitation probability — FIRST’s EPSS model scores this CVE at 0.9171, a 91.7th percentile score as of our ingestion — notably high for an eleven-year-old vulnerability.
No field is in conflict between our two sources. Our source data does not carry a fixed-version field beyond NVD’s statement that ABRT before version 2.7.1 is affected.
Why this matters
CVE-2015-5287 is one of the oldest vulnerabilities we’ve covered in this cycle, and its appearance on CISA’s KEV catalog in 2026 — more than a decade after disclosure — is a striking illustration of how long unpatched software can remain exposed, especially on legacy Linux systems where ABRT may run as a background diagnostic service that administrators rarely think to audit for security patches. The 91.7th-percentile EPSS score is unusually high for a decade-old flaw, suggesting real, current exploitation interest rather than a purely academic risk.
Any organization running legacy Red Hat-family Linux systems with ABRT installed and unpatched should treat this as an active local privilege-escalation risk, not a historical footnote.
Frequently Asked Questions
What is CVE-2015-5287?
A CVSS 7.8 symlink-attack privilege escalation vulnerability (CWE-59) in the abrt-hook-ccpp helper program of Red Hat’s Automatic Bug Reporting Tool before version 2.7.1, allowing local users to gain privileges via a predictable-filename symlink attack.
Is CVE-2015-5287 being actively exploited? Yes, per CISA’s own Known Exploited Vulnerabilities catalog, which added this CVE on August 26, 2026.
Why is a 2015 CVE showing up in a 2026 KEV feed? CISA added it to its Known Exploited Vulnerabilities catalog in August 2026 — more than a decade after initial disclosure — which typically reflects newly observed exploitation of systems that were never patched, not a new vulnerability.
Does this create a federal patching deadline? Yes. CISA KEV listing means Binding Operational Directive 26-04’s remediation timeline applies to in-scope federal agencies for this CVE.
Which version fixes this? Version 2.7.1, per NVD. Consult Red Hat’s own security advisory for distribution-specific patch guidance.
Severity, vector, and weakness classification sourced from the National Vulnerability Database record for CVE-2015-5287. Exploitation status and the August 26, 2026 catalog date sourced from CISA’s Known Exploited Vulnerabilities catalog entry. Fix reference: Red Hat Security Advisory RHSA-2015:2505 and upstream fix commit. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.