Junglewise Threat Intelligence

CVE-2026-19546: DBI arbitrary code execution via caller-influenced Profile attribute

CVE-2026-19546 · Severity: high · CVSS 8.8 · Published 2026-08-11

Vendors: CPAN.

Executive brief

DBI is a widely-used Perl database interface library that enables applications to connect to and query databases. A vulnerability allows arbitrary code execution through a crafted Profile attribute, potentially letting an attacker run malicious code on systems running affected Perl applications that use DBI.

Technical details

DBI contains an incomplete fix for CVE-2026-14380, leaving a code execution vulnerability reachable via a caller-influenced Profile attribute. The vulnerability allows arbitrary code execution without requiring authentication or special privileges, though the exact attack preconditions (such as whether user interaction or database connection setup is required) are not detailed in the advisory. An attacker can exploit this to execute arbitrary code in the context of the application using DBI. A patch is available in Red Hat Enterprise Linux 10 and 10.2 via perl-DBI version 1.643-26.el10_2.4 and later.

Affected products

  • CPAN DBI prior to 1.643-26.el10_2.4 (Red Hat builds)

Timeline

  • 2026-08-11: disclosed
  • 2026-09-09: advisory
  • 2026-09-09: patched

References