CVE-2020-26880: Debian Linux

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Sympa through 6.2.57b.2 allows a local privilege escalation from the sympa user account to full root access by modifying the sympa.conf configuration file (which is owned by sympa) and parsing it through the setuid sympa_newaliases-wrapper executable.

Affected products

  • Debian Debian Linux: version 9.0 only
  • Fedoraproject Fedora: version 32 only; version 33 only; version 34 only
  • Sympa Sympa: up to and including 6.2.56; version 6.2.57 only

Published 2020-10-07. Last modified 2026-06-17.