PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-74859 Red Hat CVE debrief

The gnome-tweaks shell theme installer does not validate ZIP archive member paths, allowing crafted archives to write files outside ~/.themes via path traversal, absolute paths, or symlinks. This vulnerability can lead to unauthorized file writes, elevation of privileges, or data tampering. System administrators and users of gnome-tweaks should assess exposure and prioritize remediation, especially when using untrusted theme sources. The impact requires verification of affected versions and remediation steps.

Vendor
Red Hat
Product
Red Hat Enterprise Linux 8
CVSS
MEDIUM 6.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-08
Original CVE updated
2026-09-08
Advisory published
2026-09-08
Advisory updated
2026-09-08

Who should care

System administrators and users of gnome-tweaks, especially those who install themes from untrusted sources, should assess exposure and prioritize remediation. This includes reviewing the official advisory and CVE record to validate affected scope, severity, and vendor guidance, and planning vendor-supported updates or mitigations through normal change control where exposure is confirmed.

Why it matters

The gnome-tweaks shell theme installer vulnerability allows crafted ZIP archives to write files outside ~/.themes, potentially leading to unauthorized file writes, elevation of privileges, or data tampering. System administrators and users of gnome-tweaks should assess exposure and prioritize remediation, especially when using untrusted theme sources. The impact requires verification of affected versions and remediation steps.

  • Potential for unauthorized file writes outside ~/.themes
  • Possible elevation of privileges or data tampering
  • Requires verification of affected versions and remediation steps

Technical summary

The gnome-tweaks shell theme installer extracts user-supplied ZIP archives without validating archive member paths, allowing crafted archives to write files outside ~/.themes. This vulnerability can be exploited through path traversal, absolute paths, or symlinks, potentially leading to unauthorized file writes, elevation of privileges, or data tampering. System administrators and users of gnome-tweaks should assess exposure and prioritize remediation, especially when using untrusted theme sources. The impact requires verification of affected versions and remediation steps.

Defensive priority

Assess exposure and prioritize remediation for systems using gnome-tweaks with untrusted theme sources.

Recommended defensive actions

  • Assess gnome-tweaks usage and exposure to untrusted theme sources
  • Verify gnome-tweaks installation and configuration
  • Monitor for suspicious theme installation activity
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Review compensating controls for exposed systems while remediation is scheduled and verified

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, but additional information on affected versions and remediation is limited. Further verification is needed to determine the full scope of the vulnerability and to identify potential mitigations. Defenders should review the official advisory and CVE record to validate affected scope, severity, and vendor guidance.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-74859 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-74859

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-74859 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-74859

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.