← All Advisories

Red Hat Enterprise Linux 10 Vim's Security Flaw Reachable by Unauthenticated Local Attackers (CVSS 7.8)

Last refreshed2026-10-05

Status: UPDATED  |  Advisory ID: CVE-2026-43961

Key Details

CVECVE-2026-43961
CVSS Score / Version7.8 (High) / CVSS v3.1
Updated2026-09-22
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is none; user interaction is required; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsRed Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 7, Red Hat Hardened Images, and vim vim
Classified asCWE-94 (Improper Control of Generation of Code ('Code Injection'))
Exploitation prediction (EPSS)0.22% probability of exploitation in the next 30 days (11% percentile) -- FIRST.org's EPSS model.

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Red HatRed Hat Enterprise Linux 10
Red HatRed Hat Enterprise Linux 9
Red HatRed Hat Enterprise Linux 7
Red HatRed Hat Hardened Images
vimvim
SubsystemsOT Supporting Infrastructure
SectorsMultiple

What to Know

A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expression fragments can break out of the quoted context during mark/unmark operations, allowing arbitrary Vimscript execution. This can be leveraged to run shell commands with the privileges of the user running Vim. (NVD)

What to Do

Monitor Red Hat's and vim's web pages for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-43961
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-43961