Threat Advisory

A command injection flaw was found in rpm (CVE-2026-95521)

HIGH CVSS 7.8 September 24, 2026

What happened

A command injection vulnerability has been identified in the rpm package management tool, affecting multiple versions of Red Hat Enterprise Linux as well as Hardened Images. The flaw, designated CVE-2026-95521, impacts situations where source or spec files with basenames containing a %() macro are installed or rebuilt using rpm. Exploiting this flaw involves an attacker-controlled shell command being executed through the popen() function during the relocation of source file lists. This process permits arbitrary command execution, potentially compromising the affected system.

The severity level has been rated as high, primarily because the vulnerability enables remote exploitation if an attacker already has local access to the host and can influence the processing of untrusted source RPMs. The attack requires user interaction, such as opening a malicious file or visiting a compromised webpage, and does not necessitate prior access or privileges. The scope remains limited to cases where the attacker can manipulate RPM installations or rebuilds with crafted source or spec filenames.

The vulnerability stems from improper handling of specific macro constructs within file basenames, which triggers unintended shell command execution during rpm operations. This flaw highlights the importance of privilege hygiene, device control, and endpoint monitoring, as network exposure conditions are not relevant for exploitability.

Who is affected

Organisations running Red Hat Enterprise Linux versions 6, 7, 8, 9, or 10, as well as those using Hardened Images, may be affected by this vulnerability. The impact is limited to environments where untrusted or malicious source RPMs are processed by rpm, particularly during installation or rebuilding operations. Since no patch is currently available, affected deployments should monitor for unusual activity related to RPM processing, ensuring robust supply chain security practices.

Recommended actions

  1. Ensure strict control over the processing of source RPMs, verifying their origin and integrity before installation or rebuilding.
  2. Implement endpoint security measures that monitor for anomalous activities related to RPM operations, with particular attention to file manipulations involving source or spec filenames containing macro constructs.
  3. Maintain privilege hygiene by restricting access to system package management functions and limiting rebuild capabilities to trusted administrators.
  4. Participate in ongoing vulnerability tracking and apply updates or mitigations as they become available from the vendor or security advisories.

Indicators of compromise

No specific indicators of compromise are provided at this time.

Affected

Vendors: Red Hat

Products: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Hardened Images

Is your organisation exposed?

Argos matches live threat intelligence to your own asset inventory and tells you what actually affects you.

Discover Argos

At a glance

Severityhigh
CVSS7.8
CVECVE-2026-95521
PublishedSeptember 24, 2026
VendorRed Hat
ProductsRed Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Hardened Images

Get in touch

We respond within 1 hour on weekdays
Exeo Logo White Transparent