Path traversal in tar - CVE-2026-24842
Published: January 28, 2026
Vulnerability identifier: #VU122099
CSH Severity: Medium
CVSS v4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-24842
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences in lib/unpack.js. A remote attacker can send a specially crafted HTTP request and read or overwrite arbitrary files on the system.
Affected software
tar
Voice Gateway
IBM Watson Discovery for IBM Cloud Pak for Data
Jira Service Management Data Center
Confluence Data Center
Jira Software Data Center
AppDynamics NodeJS Agent
watsonx Code Assistant On Prem
Maximo Application Suite - Visual Inspection Component
Fedora
linux-sgx
Voice Gateway
IBM Watson Discovery for IBM Cloud Pak for Data
Jira Service Management Data Center
Confluence Data Center
Jira Software Data Center
AppDynamics NodeJS Agent
watsonx Code Assistant On Prem
Maximo Application Suite - Visual Inspection Component
Fedora
linux-sgx
How to mitigate CVE-2026-24842
Install updates from vendor's website.
tar - update to 7.5.7
Voice Gateway - addressed in versions 1.0.8.17, 1.0.8.18, 1.0.8.24, 1.0.8.29
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.1
watsonx Code Assistant On Prem - update to 5.3.1
Jira Service Management Data Center - addressed in versions 10.3.18, 11.3.3
Confluence Data Center - addressed in versions 9.2.19, 10.2.10
Maximo Application Suite - Visual Inspection Component - addressed in versions 8.9.21, 9.0.17, 9.1.10
Jira Software Data Center - addressed in versions 10.3.18, 11.3.3
AppDynamics NodeJS Agent - update to 25.12.1
linux-sgx - update to 2.26-34.fc43
Voice Gateway - addressed in versions 1.0.8.17, 1.0.8.18, 1.0.8.24, 1.0.8.29
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.1
watsonx Code Assistant On Prem - update to 5.3.1
Jira Service Management Data Center - addressed in versions 10.3.18, 11.3.3
Confluence Data Center - addressed in versions 9.2.19, 10.2.10
Maximo Application Suite - Visual Inspection Component - addressed in versions 8.9.21, 9.0.17, 9.1.10
Jira Software Data Center - addressed in versions 10.3.18, 11.3.3
AppDynamics NodeJS Agent - update to 25.12.1
linux-sgx - update to 2.26-34.fc43
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Path traversal in tar
- Multiple vulnerabilities in IBM Voice Gateway
- Fedora 43 update for linux-sgx
- Multiple vulnerabilities in IBM watsonx Code Assistant On Prem
- Splunk AppDynamics NodeJS Agent update for third-party components
- Jira Service Management Data Center update for node-tar
- Jira Software Data Center update for node-tar
- Confluence Data Center update for node-tar
- IBM Watson Discovery Cartridge update for node-tar
- IBM Maximo Application Suite - Visual Inspection Component update for node-tar