Description
A flaw was found in DBI. This is a fix for a partial fix for CVE-2026-14380 for RHEL 9.8.z and 10.2.z.

For a detailed Statement, Description and Mitigation please reffer to the original https://access.redhat.com/security/cve/cve-2026-19546.
Published: 2026-08-11
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the DBI module allows an attacker to execute arbitrary code by influencing the profile attribute passed by a caller. The vulnerability is a code injection flaw (CWE-94), which can compromise both confidentiality and integrity of affected systems. The impact is the execution of any code with the privileges of the running DBI process, potentially leading to full system compromise.

Affected Systems

Red Hat Enterprise Linux 9 and 10 are affected, with the fix applied only for the 9.8.z and 10.2.z release streams. The issue arises from a partial patch for the earlier CVE-2026‑14380, meaning older RHEL 9 and 10 releases remain vulnerable unless updated to the listed releases. No other RHEL versions are explicitly cited, but the presence of Red Hat Enterprise Linux 6, 7, and 8 in the CNA product list suggests that they may also need review for possible exposure.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity, but the EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves a trusted process that can set the caller‑influenced profile attribute; the attacker would need to influence or replace that process or supply malicious input via a component leveraging DBI. Because the description does not disclose remote exploitation details, it is inferred that the vulnerability requires local or privileged access to the affected process.

Generated by OpenCVE AI on August 11, 2026 at 23:05 UTC.

Remediation

Vendor Workaround

For a detailed Statement, Description and Mitigation please reffer to the original https://access.redhat.com/security/cve/cve-2026-19546.


OpenCVE Recommended Actions

  • Apply the latest Red Hat Enterprise Linux 9.8.z or 10.2.z patches that address the DBI flaw
  • If a system cannot be upgraded immediately, review all DBI usage to ensure that callers cannot supply uncontrolled profile attributes, and restrict privileges accordingly
  • Consult the Red Hat Security Advisory at https://access.redhat.com/security/cve/cve-2026-19546 for detailed mitigation guidance

Generated by OpenCVE AI on August 11, 2026 at 23:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Tue, 11 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in DBI. This is a fix for a partial fix for CVE-2026-14380 for RHEL 9.8.z and 10.2.z. For a detailed Statement, Description and Mitigation please reffer to the original https://access.redhat.com/security/cve/cve-2026-19546.
Title Dbi: incomplete fix for cve-2026-14380 dbi: arbitrary code execution via caller-influenced profile attribute
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-94
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-08-12T13:42:10.424Z

Reserved: 2026-08-11T13:54:21.233Z

Link: CVE-2026-19546

cve-icon Vulnrichment

Updated: 2026-08-12T13:36:39.743Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T16:17:31.767

Modified: 2026-08-14T19:07:46.080

Link: CVE-2026-19546

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-11T09:09:00Z

Links: CVE-2026-19546 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T10:41:12Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')