Improper access control in erb - CVE-2026-41316

 

Improper access control in erb - CVE-2026-41316

Published: April 21, 2026 / Updated: August 7, 2026


Vulnerability identifier: #VU126644
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-41316
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to improper access control in ERB#def_module, ERB#def_method, and ERB#def_class when deserializing untrusted data with Marshal.load. A remote attacker can supply crafted serialized data to bypass the @_init guard and execute arbitrary code.

Exploitation requires both erb and activesupport to be loaded.


Affected software

erb
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - AUS
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support
Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support
Basesystem Module
openEuler
Metasploit
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
rubygem-rss
rubygem-abrt
rubygem-abrt-doc
rubygem-mysql2
rubygem-mysql2-doc
rubygem-io-console
rubygem-typeprof
rubygem-pg-doc
rubygem-pg
rubygem-did_you_mean
rubygem-racc
rubygem-irb
rubygem-power_assert
libruby2_5-2_5
ruby2.5
ruby2.5-stdlib
ruby2.5-debugsource
ruby2.5-debuginfo
ruby2.5-stdlib-debuginfo
ruby2.5-devel-extra
libruby2_5-2_5-debuginfo
ruby2.5-devel
rubygem-bundler
rubygem-json
rubygem-rbs
ruby (Red Hat package)
rubygem-openssl
rubygem-bigdecimal
ruby-bundled-gems
ruby
ruby-debuginfo
ruby-debugsource
ruby-devel
ruby-help
ruby-irb
rubygem-rexml
ruby-libs
ruby-default-gems
ruby-doc
rubygems-devel
rubygems
rubygem-test-unit
rubygem-psych
rubygem-minitest
rubygem-rdoc
rubygem-rake
IBM Aspera Orchestrator

How to mitigate CVE-2026-41316

Install security update from vendor's website.

erb - addressed in versions 4.0.3.1, 4.0.4.1, 6.0.1.1, 6.0.4
Metasploit - update to 6.4.126
rubygem-rss - update to 0.2.9-152
rubygem-rss - addressed in versions 0.3.1-6, 0.3.1-7
rubygem-abrt - update to 0.4.0-1
rubygem-abrt-doc - update to 0.4.0-1
rubygem-mysql2 - update to 0.5.5-1
rubygem-mysql2-doc - update to 0.5.5-1
rubygem-io-console - update to 0.6.0-152
rubygem-io-console - addressed in versions 0.7.1-6, 0.7.1-7
rubygem-typeprof - update to 0.21.3-152
rubygem-typeprof - addressed in versions 0.21.9-6, 0.21.9-7
rubygem-pg-doc - update to 1.5.4-1
rubygem-pg - update to 1.5.4-1
rubygem-did_you_mean - update to 1.6.3-152
rubygem-racc - addressed in versions 1.7.3-6, 1.7.3-7
rubygem-irb - addressed in versions 1.13.1-6, 1.13.1-7
rubygem-power_assert - addressed in versions 2.0.3-6, 2.0.3-7
libruby2_5-2_5 - update to 2.5.9-150700.24.11.1
ruby2.5 - update to 2.5.9-150700.24.11.1
ruby2.5-stdlib - update to 2.5.9-150700.24.11.1
ruby2.5-debugsource - update to 2.5.9-150700.24.11.1
ruby2.5-debuginfo - update to 2.5.9-150700.24.11.1
ruby2.5-stdlib-debuginfo - update to 2.5.9-150700.24.11.1
ruby2.5-devel-extra - update to 2.5.9-150700.24.11.1
libruby2_5-2_5-debuginfo - update to 2.5.9-150700.24.11.1
ruby2.5-devel - update to 2.5.9-150700.24.11.1
rubygem-bundler - addressed in versions 2.5.22-6, 2.5.22-7
rubygem-json - update to 2.6.3-152
rubygem-json - addressed in versions 2.7.2-6, 2.7.2-7
rubygem-rbs - update to 2.8.2-152
ruby (Red Hat package) - addressed in versions 3.0.4-160.2.el9_0, 3.0.7-162.el9_4.2, 3.0.7-166.el9_7, 3.3.10-11.el10_0.1
rubygem-openssl - update to 3.1.0-152
rubygem-bigdecimal - update to 3.1.3-152
rubygem-bigdecimal - addressed in versions 3.1.5-6, 3.1.5-7
ruby-bundled-gems - update to 3.2.2-152
ruby - update to 3.2.2-152
ruby-debuginfo - update to 3.2.2-152
ruby-debugsource - update to 3.2.2-152
ruby-devel - update to 3.2.2-152
ruby-help - update to 3.2.2-152
ruby-irb - update to 3.2.2-152
rubygem-rexml - update to 3.2.5-152
ruby - addressed in versions 3.3.9-7, 3.3.10-6
ruby-bundled-gems - addressed in versions 3.3.9-7, 3.3.10-6
ruby-devel - addressed in versions 3.3.9-7, 3.3.10-6
ruby-libs - addressed in versions 3.3.9-7, 3.3.10-6
ruby-default-gems - addressed in versions 3.3.9-7, 3.3.10-6
ruby-doc - addressed in versions 3.3.9-7, 3.3.10-6
rubygem-rexml - addressed in versions 3.3.9-7, 3.4.4-6
rubygem-rbs - addressed in versions 3.4.0-6, 3.4.0-7
rubygems-devel - update to 3.4.10-152
rubygems - update to 3.4.10-152
rubygem-test-unit - update to 3.5.7-152
rubygems-devel - addressed in versions 3.5.22-6, 3.5.22-7
rubygems - addressed in versions 3.5.22-6, 3.5.22-7
rubygem-test-unit - addressed in versions 3.6.1-6, 3.6.1-7
IBM Aspera Orchestrator - update to 4.1.5
rubygem-psych - update to 5.0.1-152
rubygem-psych - addressed in versions 5.1.2-6, 5.1.2-7
rubygem-minitest - update to 5.16.3-152
rubygem-minitest - addressed in versions 5.20.0-6, 5.20.0-7
rubygem-rdoc - update to 6.5.0-152
rubygem-rdoc - addressed in versions 6.6.3.1-6, 6.6.3.1-7
rubygem-rake - update to 13.0.6-152
rubygem-rake - addressed in versions 13.1.0-6, 13.1.0-7

External References

Related Security Bulletins