8.6
CVE-2026-34714
- EPSS 0.59%
- Veröffentlicht 30.03.2026 18:27:55
- Zuletzt bearbeitet 01.09.2026 13:18:58
- Erkennungen
Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.59% | 0.437 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8.6 | 1.8 | 6 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
|
| MITRE | 9.2 | 2.5 | 6 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
|
| 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | 8.6 | 1.8 | 6 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
|
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CWE-917 Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
The product constructs all or part of an expression language (EL) statement in a framework such as a Java Server Page (JSP) using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended EL statement before it is executed.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://www.openwall.com/lists/oss-security/2026/03/30/3
https://github.com/vim/vim/commit/664701eb7576edb7c7c7d9f2d600815ec1f43459
https://github.com/vim/vim/releases/tag/v9.2.0272
http://www.openwall.com/lists/oss-security/2026/04/02/4
http://www.openwall.com/lists/oss-security/2026/04/02/5
http://www.openwall.com/lists/oss-security/2026/04/03/6
https://bugzilla.redhat.com/show_bug.cgi?id=2453139
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34714.json
https://github.com/vim/vim/security/advisories/GHSA-2gmj-rpqf-pxvh
https://access.redhat.com/security/cve/CVE-2026-34714