---
id: CVE-2026-34982
title: 'Vim is an open source, command line text editor'
summary: >-
  Vim is an open source, command line text editor. Prior to version 9.2.0276, a
  modeline sandbox bypass in Vim allows arbitrary OS command execution when a
  user opens a crafted file. The `complete`, `guitabtooltip` and `printheader`
  option…
severity: high
cvss: 8.2
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N'
cwe:
  - CWE-78
vendor: vim
product: vim
affected:
  - vim < 9.2.0276
patched:
  - vim 9.2.0276
published: '2026-04-06'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T13:18:05.033'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-34982'
references:
  - url: 'https://github.com/vim/vim/commit/75661a66a1db1e1f3f1245c615'
    label: security-advisories@github.com
  - url: 'https://github.com/vim/vim/releases/tag/v9.2.0276'
    label: security-advisories@github.com
  - url: 'https://github.com/vim/vim/security/advisories/GHSA-8h6p-m6gr-mpw9'
    label: security-advisories@github.com
  - url: 'http://www.openwall.com/lists/oss-security/2026/04/01/1'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2026:11389'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:11509'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:11510'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:19073'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:19224'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:21275'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:22634'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:28049'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:28050'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:28133'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:30078'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:30087'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:30088'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:30089'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:30900'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:33453'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:34476'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:34477'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:36004'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:36005'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:36006'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:56786'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:56853'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:56911'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:57402'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:57483'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:58981'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:59831'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:60019'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:65839'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:68711'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/security/cve/CVE-2026-34982'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2455400'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34982.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-34982'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-34982'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69128'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
epss: 0.0047
epssPercentile: 0.39844
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-04-06T00:00:00+00:00'
ingestedAt: '2026-07-01T03:50:34.546Z'
---

## Overview

Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary OS command execution when a user opens a crafted file. The `complete`, `guitabtooltip` and `printheader` options are missing the `P_MLE` flag, allowing a modeline to be executed. Additionally, the `mapset()` function lacks a `check_secure()` call, allowing it to be abused from sandboxed expressions. Commit 9.2.0276 fixes the issue.

## Affected

- `vim < 9.2.0276`

## Remediation

Upgrade past the affected range:

- `vim 9.2.0276`

## Vendor advisories

- **RHSA-2026:68711** · Red Hat · fixed in: Red Hat Enterprise Linux Server (v. 7 ELS) · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68711)
- **RHSA-2026:59831** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.12 · released 2026-09-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:59831)
- **RHSA-2026:65839** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.13 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:65839)
- **RHSA-2026:56786** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.14 · released 2026-08-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:56786)
- **RHSA-2026:56911** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.15 · released 2026-08-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:56911)
- **RHSA-2026:56853** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.16 · released 2026-08-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:56853)
- **RHSA-2026:60019** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.17 · released 2026-09-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:60019)
- **RHSA-2026:57483** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.18 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:57483)
- **RHSA-2026:57402** · Red Hat · fixed in: Red Hat OpenShift Container Platform 4.19 · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:57402)
- **RHSA-2026:30900** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0), Red Hat Enterprise Linux BaseOS EUS (v. 10.0) · released 2026-06-29 · [advisory](https://access.redhat.com/errata/RHSA-2026:30900)
- **RHSA-2026:11389** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10), Red Hat Enterprise Linux BaseOS (v. 10) · released 2026-04-28 · [advisory](https://access.redhat.com/errata/RHSA-2026:11389)
- **Red Hat VEX** · Important · affected: Red Hat Hardened Images, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Hardened Images, Red Hat OpenShift Container Platform 4 · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34982.json)
- **RHSA-2026:69128** · Red Hat · fixed in: Red Hat Enterprise Linux Server -EXTENSION(v. 6 ELS-EXTENSION) · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69128)
