CVE-2026-88889: Mend Mend-Renovate-CE

High severity, CVSS 7.8. EPSS: 1% chance of exploitation in the next 30 days.

Renovate before 44.14.7 contains a command injection vulnerability in the Maven Wrapper manager that allows attackers to execute arbitrary commands by specifying a malicious distributionType parameter in maven-wrapper.properties. Attackers can inject shell commands through unescaped distributionType values to achieve remote code execution when Renovate processes Maven Wrapper updates in binarySource=docker mode.

Affected products

  • Mend Mend-Renovate-CE: before 15.4.0 (fixed in 15.4.0)
  • Mend Mend-Renovate-Enterprise-Edition: before 10.4.0 (fixed in 10.4.0)
  • Mend Renovate-CE: before 15.4.0 (fixed in 15.4.0)
  • Mend Renovate-EE-Server: before 15.4.0 (fixed in 15.4.0)
  • Mend Renovate-EE-Worker: before 15.4.0 (fixed in 15.4.0)
  • Renovatebot Renovate: before 44.14.7 (fixed in 44.14.7)

Published 2026-09-10. Last modified 2026-09-29.