Impact: an administrator who manages users against an external/federated LDAP directory via `yast2 users` triggers root command execution the moment they view or edit that particular user's "Password Settings" tab. No "join domain" or trust setup is required, just browsing/editing one user entry.
This issue affects yast2-users through 5.0.8.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://bugzilla.suse.com/show_bug.cgi?id=1272839 |
|
Tue, 01 Sep 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An OS command injection vulnerability was found in yast2-users. When displaying the "Password Settings" tab of a user, get_password_term() in src/include/users/dialogs.rb read the shadowLastChange and shadowExpire fields with GetString(), which performs no numeric validation, and passed the resulting string to format_days_after_epoch(). That helper interpolated the value into a shell command executed via Ruby backticks without quoting or escaping. Impact: an administrator who manages users against an external/federated LDAP directory via `yast2 users` triggers root command execution the moment they view or edit that particular user's "Password Settings" tab. No "join domain" or trust setup is required, just browsing/editing one user entry. This issue affects yast2-users through 5.0.8. | |
| Title | yast2-users: OS command injection via LDAP-supplied shadowLastChange/shadowExpire attribute | |
| Weaknesses | CWE-1287 CWE-78 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: suse
Published:
Updated: 2026-09-01T12:24:32.985Z
Reserved: 2026-07-06T11:59:28.119Z
Link: CVE-2026-59680
No data.
Status : Received
Published: 2026-09-01T10:17:13.160
Modified: 2026-09-01T10:17:13.160
Link: CVE-2026-59680
No data.
OpenCVE Enrichment
Updated: 2026-09-01T10:30:13Z