OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-95521

HIGH · CVSS 7.8 EPSS 0.58%

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

A command injection vulnerability in the rpm package manager allows an attacker to execute arbitrary shell commands by manipulating the source or spec file basenames of a source RPM containing a %() macro construct. This poses a significant risk to users who install or rebuild untrusted .src.rpm files, as it can lead to unauthorized command execution with the privileges of the invoking user. Organizations using rpm for package management should prioritize addressing this vulnerability to mitigate potential exploitation.

CVE
CVE-2026-95521
Severity
HIGH
CVSS
7.8
EPSS
0.58%

Original NVD Description

A command injection flaw was found in rpm. Installing or rebuilding a source RPM whose source or spec file basenames contain a %() macro construct causes rpm to execute an attacker-controlled shell command via popen() while relocating the source file list. This allows arbitrary command execution as the invoking (typically non-root) user, simply by installing, rebuilding, or otherwise processing an untrusted .src.rpm.