CVE-2026-84838 A flaw was found in rpmuncompress. This command… — CVE Notify — TG.ME

🚨 CVE-2026-84838
A flaw was found in rpmuncompress. This command injection vulnerability allows a local attacker to execute arbitrary commands. This occurs when rpmuncompress processes a specially crafted archive filename containing shell metacharacters, which are not properly escaped before being passed to shell command strings. Successful exploitation requires user interaction, where a user or automated workflow invokes rpmuncompress on the malicious file, leading to high impact on the confidentiality, integrity, and availability of data accessible to the invoking user.

🎖@cveNotify
Redhat
CVE-2026-84838 - Red Hat Customer Portal
CVE Details App
September 2, 2026 50