CVE-2026-38945 is a command injection vulnerability in Raynet rvia version 12.6 Update 8 and earlier, including builds such as 12.6.4392.49-amd64.deb. The issue arises in rvia's Java-based search functionality, which invokes the Unix find command with improperly terminated search criteria. A crafted filesystem path that matches the malformed search expression can break out of the intended command context and cause unintended command execution. The available advisory states this can result in arbitrary Java code execution on the affected system.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Small standalone local privilege-escalation repository for CVE-2026-38945 against Raynet RayVentory Scan Engine / Inventory Agent on Linux. The repo contains one Bash exploit script (CVE-2026-38945.sh), a README explaining the bug and exploitation flow, and two illustrative images. The exploit is not framework-based. The main script supports two modes: vulnerability checking (-t) and exploitation (-e), with mandatory distro selection (-d deb|rpm). It determines architecture via uname -m, verifies whether the rvia package is installed, and compares installed versions against hardcoded fixed-version thresholds for deb and rpm builds across x86, x86_64, and ARM/aarch64. This makes it both a checker and an exploit. Exploitation is purely local. The script creates an attacker-controlled directory tree matching the Java search pattern (jdk/bin/java) under /tmp or /dev/shm, preferring a mount without nosuid. It writes a fake java shell script that copies /bin/sh to the same directory and sets the SUID bit. It then checks whether the current user can run /opt/rvia/rvia via sudo in a way that includes the oracle option; if so, it invokes the binary to trigger RayVentory's vulnerable Java auto-discovery logic. The README also notes the same primitive may be reachable through privileged cron execution configured by rvia, even without direct sudo invocation. The exploit targets a path-traversal / improper search-criteria bug in RayVentory's Java detection command. Because the exclusion paths in the find command are malformed, attacker-created paths such as /tmp/jdk/bin/java can be discovered and executed by the privileged process. Successful exploitation yields a local root shell through a SUID copy of /bin/sh. Overall, this is an operational PoC for local privilege escalation with a hardcoded payload rather than a generalized weaponized framework module.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.