Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4309 articles · 196689 vulns · 37/41 feeds (7d)
← Back to list
7.1
CVE-2026-19589PATCHED
hashi · packer

Packer vulnerable to arbitrary file write via crafted plugin archive during installation

Description

Packer up to 1.15.4 is vulnerable to an issue in the third-party plugin installer that may allow unintended file system modification and could lead to code execution. A user who installs a plugin from a malicious or compromised source may be affected. This vulnerability (CVE-2026-19589) is fixed in Packer 1.16.0.

Affected Products

VendorProductVersions
hashipacker1.7.0

References

  • https://discuss.hashicorp.com/t/hcsec-2026-29-packer-vulnerable-to-arbitrary-file-write-via-crafted-plugin-archive-during-installation/77654

Related News (1 articles)

Tier C
VulDB7d ago
CVE-2026-19589 | HashiCorp Packer up to 1.15.4 Plugin Installer code injection
→ No new info (linked only)
CVSS 3.17.1 HIGH
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
1.16.0
CWECWE-22
PublishedAug 17, 2026
Trending Score9
Source articles1
Independent1
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2026-14978
Unicode normalization mismatch in go-slug ignore pattern matching may bypass intended file exclusions
Trending: 33
CRITICALCVE-2026-16498
terraform-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode
Trending: 13
HIGHCVE-2026-14869
terraform-mcp-server vulnerable to server side request forgery leading to token exposure
Trending: 11
HIGHCVE-2026-16496
terraform-mcp-server vulnerable to cross-user credential inheritance if an MCP session ID is obtained by another user
Trending: 10
HIGHCVE-2026-14886
Vault Enterprise vulnerable to cross-namespace entity deletion
Trending: 9

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 17, 2026
Discovered by ZDM
Aug 17, 2026
Patch Available
Aug 17, 2026