Ghostwire

CVE-2026-14947: A high-privileged remote attacker can upload malicious ZIP archive containing directory traversal sequences such as ../...

HIGH CVSS 0.0

Published: August 20, 2026 | Last Modified: August 20, 2026

Description

A high-privileged remote attacker can upload malicious ZIP archive containing directory traversal sequences such as ../ can escape the intended extraction directory and write files to arbitrary locations on the server, potentially achieve arbitrary code execution due to improper validation of archive entry paths before writing files to disk which could result in full system compromise.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (1 articles)

References