CVE-2026-34714: OS Command Injection
Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking PMLE.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
vimto a version that resolves this vulnerability.Fixed in 9.2.0272
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34714?
CVE-2026-34714 is considered a critical severity vulnerability due to the potential for remote code execution upon opening a crafted file.
How do I fix CVE-2026-34714?
To fix CVE-2026-34714, upgrade Vim to version 9.2.0272 or later.
What versions of Vim are affected by CVE-2026-34714?
Vim versions prior to 9.2.0272 are affected by CVE-2026-34714.
What kind of attacks can exploit CVE-2026-34714?
CVE-2026-34714 can be exploited through specially crafted files that execute arbitrary code when opened.
Is there a workaround for CVE-2026-34714?
There are no official workarounds for CVE-2026-34714; updating to the latest version is recommended.