---
id: CVE-2026-84233
title: A flaw was found in rpm
summary: >-
  A flaw was found in rpm. A local attacker could supply a specially crafted
  `.gem` filename containing RPM macro syntax. When a user or automated workflow
  invokes `rpmuncompress -x` on this file, the macro expansion occurs during
  command …
severity: high
cvss: 7
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
vendor: Red Hat
product: rpm-main
affected:
  - rpm-main (all versions)
  - rpm (all versions)
  - rpm
  - rpm
  - rpm
  - rpm
published: '2026-09-01'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T14:17:11.187'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-84233'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:66637'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2026-84233'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2478409'
    label: secalert@redhat.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-04T01:59:52.859550Z'
epss: 0.00183
epssPercentile: 0.07084
ingestedAt: '2026-10-02T14:20:32.555Z'
---

## Overview

A flaw was found in rpm. A local attacker could supply a specially crafted `.gem` filename containing RPM macro syntax. When a user or automated workflow invokes `rpmuncompress -x` on this file, the macro expansion occurs during command construction. This allows the attacker to execute arbitrary commands with the privileges of the invoking account, leading to a compromise of confidentiality, integrity, and availability.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
