{"id":"CVE-2026-95519","published":"2026-09-24T14:18:20.153","lastModified":"2026-09-25T13:17:23.940","description":"A flaw was found in rpm. An attacker can supply a crafted manifest file that, when processed by a user or automation using `rpm -q -p` or similar manifest-processing flows, leads to arbitrary code execution. This occurs because manifest entries are unexpectedly macro-expanded before being opened, allowing embedded shell commands to run with the privileges of the `rpm` process. Successful exploitation can lead to a full compromise of confidentiality, integrity, and availability for the affected account.","cvssScore":7.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwes":["CWE-78"],"vendors":[],"products":[],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-95519","tags":[]},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2470977","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}