CVE-2026-19589

HIGH CVSS 3.1: 7.1 EPSS 0.14%
Updated Aug 28, 2026
Packer
Parameter Value
CVSS 7.1 (HIGH)
Type CWE-22 (Path Traversal)
Vendor Packer
Public PoC No

Packer up to 1.15.4 is vulnerable to an issue in the third-party plugin installer that may allow unintended file system modification and could lead to code execution. A user who installs a plugin from a malicious or compromised source may be affected. This vulnerability (CVE-2026-19589) is fixed in Packer 1.16.0.

Attack Parameters

Attack Vector
Local
Requires local access
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
Required
User action required

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
High
Complete data modification
Availability
None
No disruption

CVSS Vector v3.1

Weakness Type (CWE)

Vulnerable Products

hashicorp:packer