CyberRota
← Ana sayfaya dön

CVE-2026-44604

HIGH · CVSS 7 EPSS %0.55

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-05-28T08:16:35.280 · Çekilme zamanı: 2026-06-27T06:04:35.069811+00:00

CyberRota Yorumu

Detaylı analiz gerekiyor.

CVE
CVE-2026-44604
Severity
HIGH
CVSS
7
EPSS
%0.55

Orijinal NVD Açıklaması

A command injection vulnerability was discovered in the `rpmuncompress` utility of RPM. When extracting certain archive formats (ZIP, 7z, GEM) to a specified destination directory, the tool inserts the archive's top-level folder name into a shell command without properly sanitizing it. A specially crafted archive containing shell metacharacters in its folder name can execute arbitrary commands as the user running the extraction.