PatchSiren cyber security CVE debrief
CVE-2026-88889 Renovate CVE debrief
A command injection vulnerability exists in Renovate versions before 44.14.7. The vulnerability is located in the Maven Wrapper manager and allows attackers to execute arbitrary commands by specifying a malicious distributionType parameter in maven-wrapper.properties. This can lead to remote code execution when Renovate processes Maven Wrapper updates in binarySource=docker mode.
- Vendor
- Renovate
- Product
- Renovate
- CVSS
- HIGH 8.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-10
- Original CVE updated
- 2026-09-29
- Advisory published
- 2026-09-10
- Advisory updated
- 2026-09-29
Who should care
Defenders responsible for Renovate installations should assess exposure to this vulnerability and verify the distributionType parameter in maven-wrapper.properties. This includes reviewing potential impact, performing inventory checks, and ensuring appropriate mitigations are in place. Operators, platform administrators, vulnerability management teams, and security teams may be impacted by this vulnerability and should review the situation.
Why it matters
CVE-2026-88889 is a command injection vulnerability in Renovate before 44.14.7 that allows for remote code execution. Defenders should verify exposure and assess potential impact.
- Remote code execution possible through malicious distributionType parameter
- Verification of exposure and potential for remote code execution required
- Inventory checks and verification of distributionType parameter recommended
Technical summary
The vulnerability exists in the Maven Wrapper manager of Renovate versions before 44.14.7. A malicious distributionType parameter in maven-wrapper.properties can lead to remote code execution when Renovate processes Maven Wrapper updates in binarySource=docker mode. This allows attackers to execute arbitrary commands, potentially resulting in remote code execution. Defenders should prioritize verifying exposure of Renovate installations to this vulnerability and assess the potential for remote code execution. Inventory checks and verification of the distributionType parameter in maven-wrapper.properties are recommended.
Defensive priority
Defenders should prioritize verifying exposure of Renovate installations to this vulnerability and assess the potential for remote code execution. Inventory checks and verification of the distributionType parameter in maven-wrapper.properties are recommended.
Recommended defensive actions
- Verify exposure of Renovate installations to this vulnerability
- Assess the potential for remote code execution
- Inventory checks and verification of the distributionType parameter in maven-wrapper.properties
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including its description and CVSS score of 8.5. However, additional information on affected versions, remediation steps, and potential impact is limited. Defenders should verify exposure and assess potential impact based on available information. The vulnerability exists in Renovate versions before 44.14.7 and is located in the Maven Wrapper manager, allowing attackers to execute arbitrary commands by specifying a malicious distributionType parameter in maven-wrapper.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-88889 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-88889
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-88889 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-88889
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/renovatebot/renovate/security/advisories/GHSA-f2v7-35mm-3hx7
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/renovate-before-44.14.7-command-injection-via-distributiontype
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.