Link following in node-tar - CVE-2026-29786
Published: March 9, 2026 / Updated: March 13, 2026
Vulnerability details
The vulnerability allows a remote attacker to overwrite arbitrary files on the system.
The vulnerability exists due to insecure handling of hard links inside archives. A remote attacker can supply a specially crafted archive to the application that can overwrite arbitrary files on the system with privileges of the process performing data extraction.
Affected software
IBM Watson Discovery for IBM Cloud Pak for Data
Jira Service Management Data Center
Jira Software Data Center
Maximo Application Suite - Visual Inspection Component
How to mitigate CVE-2026-29786
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.2
Jira Service Management Data Center - addressed in versions 10.3.18, 11.3.5
Maximo Application Suite - Visual Inspection Component - addressed in versions 8.9.21, 9.0.19, 9.1.12
Jira Software Data Center - addressed in versions 10.3.18, 11.3.5