Radare2 Vulnerability: Command Injection via PDB Name

Radare2 Vulnerability: Command Injection via PDB Name

The National Vulnerability Database (NVD) has detailed a critical command injection vulnerability, CVE-2026-41015, impacting radare2, a powerful reverse engineering framework. The flaw resides in the rabin2 -PP command when radare2 is configured on UNIX-based systems without SSL enabled. Attackers can exploit this by supplying a malicious PDB (Program Database) name, leading to arbitrary command execution.

While radare2 users are generally advised to pull the latest code from Git rather than relying on release versions, the window of vulnerability was exceptionally narrow. NVD notes that the affected code existed between versions 6.1.2 and 6.1.3, a period lasting less than a week. Despite this short timeframe, the severity is significant, rated as HIGH with a CVSS score of 7.4.

The Common Vulnerability Scoring System (CVSS) vector CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H indicates a local attack vector (AV:L), though the exploit requires a high complexity (AC:H) and no privileges (PR:N) or user interaction (UI:N). The impact is high across confidentiality, integrity, and availability (C:H/I:H/A:H). This vulnerability falls under CWE-78, which specifically addresses OS command injection flaws.

Related ATT&CK Techniques

🛡️ Detection Rules

5 rules · 6 SIEM formats

5 auto-generated detection rules for this incident, mapped to MITRE ATT&CK. Available in Sigma, Splunk SPL, Sentinel KQL, Elastic Lucene, QRadar AQL, and Wazuh.

high T1190 Initial Access

Web Application Exploitation Attempt — CVE-2026-41015

✓ Sigma 🔒 Splunk SPL 🔒 Sentinel KQL 🔒 Elastic 🔒 QRadar AQL 🔒 Wazuh

Want this in your SIEM's native format? Get Splunk SPL, Sentinel KQL, Elastic, QRadar AQL, or Wazuh — ready to paste.

5 Sigma rules mapped to the ATT&CK techniques from this breach — pick your SIEM and get a ready-to-paste query.

Get All SIEM Formats →

Indicators of Compromise

IDTypeIndicator
CVE-2026-41015 Command Injection radare2 before commit 9236f44
CVE-2026-41015 Command Injection radare2 rabin2 -PP with PDB name
CVE-2026-41015 Command Injection radare2 on UNIX without SSL

Related Posts

CVE-2026-40118 — Information Disclosure

CVE-2026-40118 — UDP Console provided by Arcserve contains an incorrectly specified destination in a communication channel vulnerability. When a user configures an activation server hostname...

vulnerabilityCVEinformation-disclosurecwe-941
/MEDIUM /⚑ 2 IOCs

CVE-2026-22616 — Eaton Intelligent Power Protector (IPP) software allows

CVE-2026-22616 — Eaton Intelligent Power Protector (IPP) software allows repeated authentication attempts against the web interface login page due to insufficient rate‑limiting controls. This security issue has been fixed...

vulnerabilityCVEcwe-307
/MEDIUM /⚑ 2 IOCs

CVE-2026-22615 — Due to improper input validation in one of the Eaton

CVE-2026-22615 — Due to improper input validation in one of the Eaton Intelligent Power Protector (IPP) XML, it is possible for an attacker with admin...

vulnerabilityCVEcwe-20
/MEDIUM /⚑ 2 IOCs