← Volver a CVEs
CVE-2026-26157
HIGH7.0
Descripcion
A flaw was found in BusyBox. Incomplete path sanitization in its archive extraction utilities allows an attacker to craft malicious archives that when extracted, and under specific conditions, may write to files outside the intended directory. This can lead to arbitrary file overwrite, potentially enabling code execution through the modification of sensitive system files.
Detalles CVE
Puntuacion CVSS v3.17.0
SeveridadHIGH
Vector CVSSCVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Vector de ataqueLOCAL
ComplejidadHIGH
Privilegios requeridosNONE
Interaccion usuarioREQUIRED
Publicado2/11/2026
Ultima modificacion2/12/2026
Fuentenvd
Avistamientos honeypot0
Debilidades (CWE)
CWE-73
Referencias
https://access.redhat.com/security/cve/CVE-2026-26157(secalert@redhat.com)
https://bugzilla.redhat.com/show_bug.cgi?id=2439039(secalert@redhat.com)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.