{
  "threat_severity" : "Moderate",
  "public_date" : "2026-03-30T05:00:19Z",
  "bugzilla" : {
    "description" : "FRRouting FRR: frr: FRRouting FRR: Improper access controls in EVPN Type-2 Route Handler",
    "id" : "2452939",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2452939"
  },
  "cvss3" : {
    "cvss3_base_score" : "4.2",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L",
    "status" : "draft"
  },
  "cwe" : "CWE-807",
  "details" : [ "A vulnerability has been found in FRRouting FRR up to 10.5.1. This affects the function process_type2_route of the file bgpd/bgp_evpn.c of the component EVPN Type-2 Route Handler. The manipulation leads to improper access controls. The attack can be initiated remotely. The attack is considered to have high complexity. The exploitability is reported as difficult. The identifier of the patch is 7676cad65114aa23adde583d91d9d29e2debd045. To fix this issue, it is recommended to deploy a patch.", "A flaw was found in frr package. This vulnerability, located in the EVPN Type-2 Route Handler function, allowing a remote attacker to manipulate access controls when successfully exploited. Due to the high complexity of the attack, exploitation is considered difficult. This could potentially lead to unauthorized actions within the system." ],
  "statement" : "A Moderate impact flaw was found in the FRRouting (FRR) package, specifically within the EVPN Type-2 Route Handler. This vulnerability could allow a remote attacker to manipulate access controls. Exploitation is considered difficult due to the high complexity of the attack. This affects Red Hat Enterprise Linux 8, 9, and 10.",
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 10",
    "fix_state" : "Fix deferred",
    "package_name" : "frr",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Fix deferred",
    "package_name" : "frr",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "fix_state" : "Fix deferred",
    "package_name" : "frr",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "fix_state" : "Fix deferred",
    "package_name" : "frr10",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-5107\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-5107\nhttps://github.com/FRRouting/frr/\nhttps://github.com/FRRouting/frr/commit/7676cad65114aa23adde583d91d9d29e2debd045\nhttps://github.com/FRRouting/frr/pull/21098\nhttps://vuldb.com/submit/780123\nhttps://vuldb.com/vuln/354132\nhttps://vuldb.com/vuln/354132/cti" ],
  "name" : "CVE-2026-5107",
  "mitigation" : {
    "value" : "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
    "lang" : "en:us"
  },
  "csaw" : false
}