CVE-2026-56004Disclosure

LOWCVSS 10.0 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A shellcode injection in the mercurial handler of the obs tar_scm source service before version 0.12.4 could be used by attackers able to provide a _service file to execute code as the source service or the local user checking out the malicious services

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-07-02); latest day: 2
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-07-02: 2Mentions · 2026-07-03: 2Patch / Workaround · 2026-07-03: 2Technical Details · 2026-07-02: 2Technical Details · 2026-07-03: 207-0207-03
Signal classification2 categories
Disclosure
250.0%
Patch
250.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-07-022
Disclosure2
2026-07-032
Patch2
Full discourse4 posts
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨Critical - openSUSE obs-service-tar_scm Command Injection via Mercurial Handler (CVE-2026-56004) A shellcode/OS command injection flaw (CWE-78) in the mercurial handler of the Open Build Service tar_scm source service lets an attacker who can supply a malicious _service file inject shell commands. The code executes as the OBS source service or as the local user checking out the malicious services. Since _service files drive source checkouts in OBS, a crafted package/project turns a normal build-time SCM fetch into arbitrary code execution. The flaw is remotely exploitable with no privileges and no user interaction, and CISA assessed it as automatable - a maximum-severity CVSS 10.0. 👉Upgrade obs-service-tar_scm to 0.12.4.

    Post summary

    The advisory reports a critical command‑injection vulnerability in openSUSE’s obs-service-tar_scm (CVE‑2026‑56004) and directs users to upgrade to version 0.12.4.

    00000103
    236 followersView on X
  • SecAlerts@SecAlertsCo
    Patch

    ⚙️ CVE-2026-56004: Critical command injection in obs-service-tar_scm (Open Build Service). Attackers supplying a crafted _service file can execute code via the Mercurial handler. Patch to v0.12.4 now. #openSUSE #DevSecOps https://secalerts.co/vulnerability/CVE-2026-56004?utm_campaign=x https://t.co/FHIntjf5li

    Post summary

    The tweet announces a critical command injection in obs-service-tar_scm and notes that patch v0.12.4 is available, with no mention of active exploitation or a PoC.

    0000090
    847 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-56004 A shellcode injection in the mercurial handler of the obs tar_scm source service before version 0.12.4 could be used by attackers able to provide a _service file to e… https://www.cve.org/CVERecord?id=CVE-2026-56004 ----- Traducción: CVE-2026-56004 Una… http://infoflow.cloud`

    Post summary

    Brief disclosure of CVE-2026-56004 indicating a shellcode injection flaw in the Mercurial handler of the obs tar_scm service before 0.12.4; no PoC, exploit, or patch information included.

    0000042
    91 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-56004 A shellcode injection in the mercurial handler of the obs tar_scm source service before version 0.12.4 could be used by attackers able to provide a _service file to e… https://www.cve.org/CVERecord?id=CVE-2026-56004

    Post summary

    The tweet announces CVE‑2026‑56004, describing a shellcode injection flaw in an older version of the obs tar_scm service, but does not provide any exploitation details, PoC, or patch information.

    00000781
    57.7K followersView on X

Explore more