Path traversal in VMware Tanzu velero - CVE-2026-32637
Published: August 21, 2026
Vulnerability details
The vulnerability allows a remote user to overwrite sensitive files.
The vulnerability exists due to path traversal in backup tarball extraction during restore when extracting files from a backup tarball. A remote user can upload a malicious backup tarball to cause overwrite sensitive files.
Exploitation requires compromise of the backup object storage backend.