Arbitrary Code Execution in GNU Emacs by GNU Project
CVE-2026-96269

7.5HIGH

Key Information:

Vendor

Gnu

Status
Vendor
CVE Published:
22 September 2026

What is CVE-2026-96269?

GNU Emacs versions 28.1 through 31.1 are susceptible to a vulnerability that allows arbitrary code execution when a user opens a specially crafted file. This issue arises due to the handling of untrusted values in the read-symbol-shorthands, which can impact the intern and unintern functions. The flaw exists in the default configuration and does not depend on specific user settings to be exploited, making all users of the software at risk.

Affected Version(s)

Emacs 28.1 <= 31.1

References

CVSS V4

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.