Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-84838

HIGH NVD
CVSS Score 7.8
Severity HIGH
Published Sep 02, 2026
Vendor unknown

Description

A flaw was found in rpmuncompress. This command injection vulnerability allows a local attacker to execute arbitrary commands. This occurs when rpmuncompress processes a specially crafted archive filename containing shell metacharacters, which are not properly escaped before being passed to shell command strings. Successful exploitation requires user interaction, where a user or automated workflow invokes rpmuncompress on the malicious file, leading to high impact on the confidentiality, integrity, and availability of data accessible to the invoking user.

References