CVE-2026-95519High· 7.8▾ TwilightA flaw was found in rpm. An attacker can supply a crafted manifest file that, when processed by a user or automation using `rpm -q -p` or similar manifest-processing flows, leads to arbitrary code execution. This occurs because manifest …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A flaw was found in rpm. An attacker can supply a crafted manifest file that, when processed by a user or automation using rpm -q -p or similar manifest-processing flows, leads to arbitrary code execution. This occurs because manifest entries are unexpectedly macro-expanded before being opened, allowing embedded shell commands to run with the privileges of the rpm process. Successful exploitation can lead to a full compromise of confidentiality, integrity, and availability for the affected account.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-95521High· 7.8A command injection flaw was found in rpm
CVE-2026-79079High· 7.8An issue in CrossWire Xiphos <= 4.3.2 allows a local attacker to execute arbitrary code via the src/main/url.cc and src/gtk/menu_popup.c components
CVE-2026-10805Medium· 6.7A flaw was found in NetworkManager
CVE-2025-69262High· 7.5pnpm is a package manager
CVE-2026-90959High· 8.1A path traversal vulnerability was found in pulpcore
CVE-2026-94416Medium· 6.8An authorization bypass was found in the Ansible Automation Platform (AAP) gateway