What is CVE-2026-19589?
CVE-2026-19589 is a vulnerability in Packer up to version 1.15.4, involving the third-party plugin installer that may allow unintended file system modification and code execution. Users installing plugins from malicious or compromised sources are affected. Applying the security update is recommended.
Azərbaycanca: CVE-2026-19589, Packer-in 1.15.4-ə qədər versiyalarında üçüncü tərəf plagin quraşdırıcısında aşkarlanmış boşluqdur. Bu, zərərli mənbədən plagin quraşdıran istifadəçilərin sistemində fayl modifikasiyasına və kod icrasına səbəb ola bilər. İstifadəçilərə təhlükəsizlik yaması tətbiq etmək tövsiyə olunur.
FAQ2
Which software is affected by CVE-2026-19589?
CVE-2026-19589 affects Packer up to version 1.15.4.
How can this vulnerability be exploited?
It may allow file system modification and code execution on the system of users installing plugins from a malicious source.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.