CVE-2026-34714 is a critical vulnerability affecting Vim versions prior to 9.2.0272, enabling immediate code execution when a user opens a specially crafted file due to a %{expr} injection. Rated 9.2 CRITICAL, it has a low attack complexity and requires no user interaction, allowing an attacker with local access to achieve high confidentiality and integrity impacts. Currently, there is no evidence of active exploitation, nor are public exploit modules available on platforms like Metasploit or ExploitDB. However, the vulnerability has generated some community discussion, suggesting awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.1.1390, < 9.2.0272CPE matchmatch criteria | cpe:2.3:a:vim:vim:*:*:*:*:*:*:*:* | ||
>= 0, < 9.2.0272CPE match | cpe:2.3:a:vim:vim:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.