CVE-2026-84838

A flaw was found in rpmuncompress. This command injection vulnerability allows a local attacker to execute arbitrary commands. This occurs when rpmuncompress processes a specially crafted archive filename containing shell metacharacters, which are not properly escaped before being passed to shell command strings. Successful exploitation requires user interaction, where a user or automated workflow invokes rpmuncompress on the malicious file, leading to high impact on the confidentiality, integrity, and availability of data accessible to the invoking user.

  • Published Sep 2, 2026
  • CVSS 7.8 high
  • 1.0% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-84838 at the National Vulnerability Database