CVE-2026-19589 | HashiCorp Packer up to 1.15.4 Plugin Installer code injection
A vulnerability, which was classified as critical, has been found in HashiCorp Packer up to 1.15.4. Affected by this vulnerability is an unknown functionality of the component Plugin Installer. Performing a manipulation results in code injection.
This vulnerability was named CVE-2026-19589. The attack may be initiated remotely. There is no available exploit.
It is advisable to upgrade the affected component.VulDB Recent EntriesRead More