OS Command Injection Vulnerability in Qubes OS by Qubes Inc.
CVE-2026-82636

7.9HIGH

Key Information:

Vendor

Qubes Os

Status
Vendor
CVE Published:
30 August 2026

What is CVE-2026-82636?

An OS command injection vulnerability has been identified in Qubes OS prior to version 4.3.22. The issue arises during the qvm-copy-to-vm call from dom0 to a maliciously-controlled qube. The underlying cause is the improper handling of error messages by the 'system' library, which may permit the inclusion of shell metacharacters. This flaw could potentially be exploited by an attacker to execute arbitrary commands within the host system, compromising the security model of the OS.

Affected Version(s)

Qubes OS 0

References

CVSS V3.1

Score:
7.9
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.