Arbitrary Code Execution Vulnerability in RPM by Red Hat
CVE-2026-95519

7.8HIGH

What is CVE-2026-95519?

A vulnerability has been discovered in the RPM Package Manager that allows an attacker to exploit a crafted manifest file. When the manifest is processed by a user or automation utilizing the rpm -q -p command or similar flows, it can result in arbitrary code execution. This occurs due to unexpected macro expansion of manifest entries before they are opened, enabling malicious shell commands to execute with the same privileges as the rpm process. Exploitation of this vulnerability poses significant risks, including full compromise of an affected account's confidentiality, integrity, and availability.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was discovered by Found by AISLE in partnership with Red Hat.
.