CVE-2026-73076
EUVD-2026-5623111.08.2026, 16:17
Vim is an open source, command line text editor. Prior to 9.2.0847, runtime/autoload/vimball.vim allows a crafted vimball member named .VimballRecord to overwrite the installation record with attacker-chosen commands. When vimball#RmVimball() later processes the matching record entry, the stored Ex commands, including operating-system commands invoked through :!, execute with the privileges of the user running Vim. This issue is fixed in version 9.2.0847.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| vim | vim | 𝑥 < 9.2.847 | CNA |
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| vim |
|
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| gvim |
| ||||||||||||||||||||||||
| vim |
| ||||||||||||||||||||||||
| vim-data |
| ||||||||||||||||||||||||
| vim-data-common |
| ||||||||||||||||||||||||
| vim-small |
|
Red Hat Enterprise Linux Releases
Amazon Linux Releases
Amazon Package | |||||
|---|---|---|---|---|---|
| vim-X11 |
| ||||
| vim-common |
| ||||
| vim-data |
| ||||
| vim-debuginfo |
| ||||
| vim-debugsource |
| ||||
| vim-default-editor |
| ||||
| vim-enhanced |
| ||||
| vim-enhanced-debuginfo |
| ||||
| vim-filesystem |
| ||||
| vim-minimal |
| ||||
| vim-minimal-debuginfo |
| ||||
| xxd |
| ||||
| xxd-debuginfo |
|