← All Advisories

CVE-2026-79992

Last refreshed2026-10-11

Status: UPDATED  |  Advisory ID: CVE-2026-79992

Key Details

CVECVE-2026-79992
CVSS Score / Version
7.8 (High) / CVSS v3.1
Updated2026-10-11
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Prose
attack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected products
Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 7, and Red Hat Enterprise Linux 6
Classified as
CWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'))

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Red HatRed Hat Enterprise Linux 10
Red HatRed Hat Enterprise Linux 8
Red HatRed Hat Enterprise Linux 9
Red HatRed Hat Enterprise Linux 7
Red HatRed Hat Enterprise Linux 6
SubsystemsOT Supporting Infrastructure
SectorsMultiple

What to Know

A flaw was found in Emacs TRAMP. A local attacker could exploit this vulnerability by processing maliciously crafted filenames. This occurs because TRAMP concatenates login arguments without proper sanitization, which are then passed to a local shell. Successful exploitation could lead to arbitrary code execution. (NVD)

What to Do

Monitor Red Hat's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-79992
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-79992