Arbitrary Code Execution Vulnerability in RPM by Red Hat
CVE-2026-95519
7.8HIGH
What is CVE-2026-95519?
A vulnerability has been discovered in the RPM Package Manager that allows an attacker to exploit a crafted manifest file. When the manifest is processed by a user or automation utilizing the rpm -q -p command or similar flows, it can result in arbitrary code execution. This occurs due to unexpected macro expansion of manifest entries before they are opened, enabling malicious shell commands to execute with the same privileges as the rpm process. Exploitation of this vulnerability poses significant risks, including full compromise of an affected account's confidentiality, integrity, and availability.
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This issue was discovered by Found by AISLE in partnership with Red Hat.