Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-59680— yast2-users: OS command injection via LDAP-supplied shadowLastChange/shadowExpire attribute

Quick assessment

Affected
SUSE yast2-users
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

以下是该漏洞描述的中文翻译: 在 yast2-users 中发现了一个操作系统命令注入漏洞。在显示用户“密码设置”选项卡时,位于 中的 函数通过 读取 和 字段。 不进行任何数值验证,并将得到的字符串直接传递给 。该辅助函数将数值通过 Ruby 的反引号(backticks)执行的 shell 命令进行插值,且未对数值进行加引号或转义处理。 影响: 当管理员通过 针对外部/联合 LDAP 目录管理用户时,一旦查看或编辑特定用户的“密码设置”选项卡,就会触发以 root 权限执行命令。无需配置“加入域”或信任关系,仅

CVSS 8.0 · High

Possible ATT&CK Techniques 1 AI

T1059 · Command and Scripting Interpreter
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-59680

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
yast2-users: OS command injection via LDAP-supplied shadowLastChange/shadowExpire attribute
Source: CVE Program / CVE List V5
Vulnerability Description
An OS command injection vulnerability was found in yast2-users. When displaying the "Password Settings" tab of a user, get_password_term() in src/include/users/dialogs.rb read the shadowLastChange and shadowExpire fields with GetString(), which performs no numeric validation, and passed the resulting string to format_days_after_epoch(). That helper interpolated the value into a shell command executed via Ruby backticks without quoting or escaping. Impact: an administrator who manages users against an external/federated LDAP directory via `yast2 users` triggers root command execution the moment they view or edit that particular user's "Password Settings" tab. No "join domain" or trust setup is required, just browsing/editing one user entry. This issue affects yast2-users through 5.0.8.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
SUSE yast2-users 0 ~ 5.0.8 -

II. Public POCs for CVE-2026-59680

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-59680

登录查看更多情报信息。

Vendor Advisories for CVE-2026-59680 (1)

Same Patch Batch · SUSE · 2026-09-01 · 3 CVEs total

CVE-2026-59681 8.8 HIGH yast2-auth-client: OS command injection via unsanitized Organizational Unit / dnsHostName
CVE-2026-25706 7.5 HIGH yast2-samba-client: OS command injection via attacker-controlled Organizational Unit (Acti

IV. Related Vulnerabilities

V. Comments for CVE-2026-59680

No comments yet


Leave a comment