Scworld
Critical Redis Vulnerability CVE-2026-23479 Enables Remote Code Execution
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A critical remote code execution vulnerability, CVE-2026-23479, has been identified in Redis, affecting versions from 7.2.0 onwards. This flaw, rated 8.8 by CVSS 3.1 and 7.7 by CVSS 4.0, is a use-after-free issue in the unblockClientOnKey() function. It allows an authenticated user to exploit the vulnerability via a Lua script to leak a heap pointer and manipulate client memory, ultimately redirecting execution to system(). Redis issued patches for versions 7.2.14, 7.4.9, 8.2.6, 8.4.3, and 8.6.3, urging immediate upgrades. The vulnerability has been present for over two years, increasing the risk as many Redis instances run without passwords in cloud environments. No active exploitation has been reported yet, but the potential for widespread impact remains significant.
Key Points: • CVE-2026-23479 is a critical RCE vulnerability in Redis with a CVSS score of 8.8. • The flaw allows exploitation through authenticated sessions, often granted to default users. • Redis has released patches and recommends immediate upgrades to mitigate risks.