CVE-2026-14947

A high-privileged remote attacker can upload malicious ZIP archive containing directory traversal sequences such as ../ can escape the intended extraction directory and write files to arbitrary locations on the server, potentially achieve arbitrary code execution due to improper validation of archive entry paths before writing files to disk which could result in full system compromise.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-20 09:16

Updated : 2026-09-03 16:57


NVD link : CVE-2026-14947

Mitre link : CVE-2026-14947

CVE.ORG link : CVE-2026-14947


JSON object : View

Products Affected

No product.

CWE
CWE-24

Path Traversal: '../filedir'