CVE-2026-95519

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in rpm. An attacker can supply a crafted manifest file that, when processed by a user or automation using `rpm -q -p` or similar manifest-processing flows, leads to arbitrary code execution. This occurs because manifest entries are unexpectedly macro-expanded before being opened, allowing embedded shell commands to run with the privileges of the `rpm` process. Successful exploitation can lead to a full compromise of confidentiality, integrity, and availability for the affected account.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-24: 109-24
Full discourse1 post
  • Upwind Security MDR@UpwindMDR

    🚨High - rpm Code Execution via Manifest Macro Expansion (CVE-2026-95519) rpm processes crafted manifest files via rpm -q -p (and similar query/manifest flows) where manifest entries are macro-expanded before open(), allowing embedded shell commands to execute with rpm’s privileges. This yields arbitrary code execution impacting CIA. 👉Affected: rpm (versions TBD)

    0000051
    305 followersView on X

Explore more