OS Command Injection Vulnerability in YaST2 Users by SUSE
CVE-2026-59680
8.6HIGH
What is CVE-2026-59680?
An OS command injection flaw exists in the YaST2 Users module where improper validation of user input in the Password Settings tab allows for arbitrary command execution. When an administrator views or edits a user's password settings, the application passes unsanitized data into a shell command via Ruby's backticks, resulting in potential exposure to unauthorized command execution. This vulnerability poses a significant risk, as it can be exploited simply by accessing user details without requiring additional configurations like domain joins or trust setups.
Affected Version(s)
yast2-users 0 <= 5.0.8