CVE-2026-40556: Insecure Directory Permissions in GNU nano Leading to Privilege Abuse
Published Apr 28, 2026
·Updated
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Affected Software
1 affected component
GNU Nano<9.0
Event History
Apr 28, 2026
CVE Published
via MITRE·01:54 PM
Rejected
via MITRE·01:54 PM
Data Sourced
via NVD·03:16 PM
Description
Apr 29, 2026
Rejected
via MITRE·07:17 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-40556?
CVE-2026-40556 has a medium severity due to insecure directory permissions allowing privilege abuse.
2
How do I fix CVE-2026-40556?
To fix CVE-2026-40556, update GNU nano to version 9.1 or later where the permissions issue is addressed.
3
What are the consequences of CVE-2026-40556?
The consequences of CVE-2026-40556 include potential unauthorized access to user files due to the overly permissive permissions.
4
Which versions of GNU nano are affected by CVE-2026-40556?
GNU nano versions up to 9.0 are affected by CVE-2026-40556.
5
What should I do if I cannot immediately update to fix CVE-2026-40556?
If immediate updating is not possible for CVE-2026-40556, consider changing the permissions of the ~/.local directory to restrict access.