Executive Summary
Oracle Security has published a targeted security advisory addressing a high-severity local privilege escalation vulnerability within the Oracle Cloud Infrastructure (OCI) Compute Instance Agent. Tracked under CVE-2026-52410, the flaw carries a CVSS v3.1 base score of 7.8 (High) and impacts Linux and Windows compute instances running the default management daemon.
The Oracle Cloud Agent (oracle-cloud-agent) is a core service pre-installed on standard OCI platform images to facilitate guest telemetry, automated patching, command execution via OCI Run Command, and health metrics. Exploitation of the flaw enables a low-privileged local user operating within a virtual machine to execute arbitrary commands with root privileges on Linux or SYSTEM privileges on Windows.
Technical Deep-Dive: IPC Socket Permissions Misconfiguration
The vulnerability stems from insecure discretionary access control lists (DACLs) and file permission bits assigned to the local Inter-Process Communication (IPC) Unix domain socket located at /var/run/oracle-cloud-agent/plugins.sock. Under standard configuration, the socket should only permit read/write interactions from processes running under UID 0.
However, during daemon re-initialization following dynamic plugin updates, the daemon temporarily relaxed socket permissions to world-writable (0666). A malicious low-privileged tenant process running on the VM can monitor this socket via inotify events and inject crafted JSON-RPC control messages directing the agent's plugin manager to register and execute arbitrary binary commands with elevated daemon privileges.
# Checking installed Oracle Cloud Agent version
rpm -q oracle-cloud-agent
# Output on vulnerable system: oracle-cloud-agent-1.37.2-1.el8.x86_64
# Audit socket permissions
ls -la /var/run/oracle-cloud-agent/
# Flaw allowed world-writable access during initialization window:
# srw-rw-rw- 1 root root 0 Oct 07 plugins.sock
Cloud Blast Radius: Instance Principals & Metadata Compromise
Gaining root privileges inside an OCI instance carries severe cloud-tier implications, particularly in environments utilizing OCI Instance Principals. When instance principals are enabled, the VM communicates directly with the OCI Instance Metadata Service (IMDSv2) to obtain temporary compartment authorization tokens without hardcoded credentials.
Once an attacker escalates to root, they can inspect kernel memory, bypass iptables rules restricting IMDS traffic, and dump active OAuth security tokens. This allows the attacker to pivot from a single compromised application container to manage storage buckets, databases, and network gateways across the tenant's entire cloud compartment.
Remediation Checklist
Oracle has updated instance images and deployed automatic hotfix updates across managed regions. Administrators managing persistent or customized images must take immediate action:
- Update Oracle Cloud Agent: Run the package manager to install version
1.38.0or higher:sudo yum update oracle-cloud-agent -y sudo systemctl restart oracle-cloud-agent - Enforce IMDSv2 Strict Mode: Ensure all compute instances have disabled IMDSv1 fallback and require cryptographic session tokens with a maximum time-to-live of 1 hop.
- Restrict Instance Principal Permissions: Review OCI Dynamic Group policies to ensure compute instances follow strict least-privilege principles.



