Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 473
Alerts This Week
Warning Icon 1 473

SUSE Security Update 2026 3108 1 Joe Important Command Execution

suse
Calendar Grey July 17, 2026
Scroller Suse
Critical security update for joe on SUSE addresses command execution flaws for improved stability and safety.
SUSE released an important security update for joe, addressing CVE-2026-13412, which allows arbitrary command execution via malicious tags file, applicable to several SUSE products...

Summary

## This update for joe fixes the following issue * CVE-2026-13412: arbitrary command execution via malicious tags file (bsc#1269379). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3108=1 ## Package List: * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * joe-debuginfo-4.4-150000.3.3.1 * joe-4.4-150000.3.3.1 * joe-debugsource-4.4-150000.3.3.1

References

* bsc#1269379

Cross-

* CVE-2026-13412

CVSS scores:

* CVE-2026-13412 ( SUSE ): 8.5

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

* CVE-2026-13412 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Products:

* SUSE Linux Enterprise Desktop 15 SP7

* SUSE Linux Enterprise Real Time 15 SP7

* SUSE Linux Enterprise Server 15 SP7

* SUSE Linux Enterprise Server for SAP Applications 15 SP7

* SUSE Package Hub 15 15-SP7

An update that solves one vulnerability can now be installed.

##

* https://www.suse.com/security/cve/CVE-2026-13412.html

* https://bugzilla.suse.com/show_bug.cgi?id=1269379

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:3108-1
Release Date: 2026-07-17T14:12:50Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.