CVE-2023-51786: Lustre

Critical severity, CVSS 9.1. EPSS: 0.5% chance of exploitation in the next 30 days.

An issue was discovered in Lustre versions 2.13.x, 2.14.x, and 2.15.x before 2.15.4, allows attackers to escalate privileges and obtain sensitive information via Incorrect Access Control.

Affected products

  • Lustre Lustre: from 2.12.0, before 2.15.4 (fixed in 2.15.4)

Published 2024-03-07. Last modified 2026-06-17.