Critical Redis Vulnerability CVE-2026-23479 Enables Remote Code Execution

Critical Redis Vulnerability CVE-2026-23479 Enables Remote Code Execution

First seen 4 Jun 2026, 23:38 UTC Aicerts.AiScworldGbhackersCybersecuritynewswww.wiz.io+1 83% similarity 72.0

Article Content

Browse articles
ThreatCluster

A critical remote code execution vulnerability, CVE-2026-23479, has been identified in Redis, affecting versions from 7.2.0 onwards. This flaw, rated 8.8 by CVSS 3.1 and 7.7 by CVSS 4.0, is a use-after-free issue in the unblockClientOnKey() function. It allows an authenticated user to exploit the vulnerability via a Lua script to leak a heap pointer and manipulate client memory, ultimately redirecting execution to system(). Redis issued patches for versions 7.2.14, 7.4.9, 8.2.6, 8.4.3, and 8.6.3, urging immediate upgrades. The vulnerability has been present for over two years, increasing the risk as many Redis instances run without passwords in cloud environments. No active exploitation has been reported yet, but the potential for widespread impact remains significant.

Key Points: • CVE-2026-23479 is a critical RCE vulnerability in Redis with a CVSS score of 8.8. • The flaw allows exploitation through authenticated sessions, often granted to default users. • Redis has released patches and recommends immediate upgrades to mitigate risks.

ThreatCluster AI

Timeline

2026-05-05
CVE-2026-23479 published
Redis disclosed a critical remote code execution vulnerability affecting versions 7.2.0 and later.
Aicerts.Ai
2026-05-05
Vulnerability details revealed
The vulnerability is a use-after-free flaw in the unblockClientOnKey() function, allowing RCE.
Scworld
2026-06-04
Patches released
Redis released patches for multiple versions, urging users to upgrade immediately to mitigate the vulnerability.
Aicerts.Ai

Community

Browse all →

Tracked Entities in This Story