← Back to CVEs
CVE-2026-26157
HIGH7.0
Description
A flaw was found in BusyBox. Incomplete path sanitization in its archive extraction utilities allows an attacker to craft malicious archives that when extracted, and under specific conditions, may write to files outside the intended directory. This can lead to arbitrary file overwrite, potentially enabling code execution through the modification of sensitive system files.
CVE Details
CVSS v3.1 Score7.0
SeverityHIGH
CVSS VectorCVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack VectorLOCAL
ComplexityHIGH
Privileges RequiredNONE
User InteractionREQUIRED
Published2/11/2026
Last Modified2/12/2026
Sourcenvd
Honeypot Sightings0
Weaknesses (CWE)
CWE-73
References
https://access.redhat.com/security/cve/CVE-2026-26157(secalert@redhat.com)
https://bugzilla.redhat.com/show_bug.cgi?id=2439039(secalert@redhat.com)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.