OS Command Injection Vulnerability in YaST2 Users by SUSE
CVE-2026-59680

8.6HIGH

Key Information:

Vendor

Suse

Vendor
CVE Published:
1 September 2026

What is CVE-2026-59680?

An OS command injection flaw exists in the YaST2 Users module where improper validation of user input in the Password Settings tab allows for arbitrary command execution. When an administrator views or edits a user's password settings, the application passes unsanitized data into a shell command via Ruby's backticks, resulting in potential exposure to unauthorized command execution. This vulnerability poses a significant risk, as it can be exploited simply by accessing user details without requiring additional configurations like domain joins or trust setups.

Affected Version(s)

yast2-users 0 <= 5.0.8

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alperen Keskin
.