Busybox: busybox: arbitrary file overwrite and potential code execution via incomplete path sanitization
41Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 7epss 0.7%
from disclosure to weapon78 days
Published on NVDFeb 11
1st PoC+78d
exploitation probability
0.7%top 50% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
A flaw was found in BusyBox. Incomplete path sanitization in its archive extraction utilities allows an attacker to craft malicious archives that when extracted, and under specific conditions, may write to files outside the intended directory. This can lead to arbitrary file overwrite, potentially enabling code execution through the modification of sensitive system files.
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
public PoCs found — 1
exploitdbwww.exploit-db.com/exploits/52538unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
https://access.redhat.com/errata/RHSA-2026:13831https://access.redhat.com/security/cve/CVE-2026-26157https://bugzilla.redhat.com/show_bug.cgi?id=2439039https://cert-portal.siemens.com/productcert/html/ssa-253495.htmlhttps://git.busybox.net/busybox/commit/archival?id=3fb6b31c716669e12f75a2accd31bb7685b1a1cbhttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-26157.json