Path traversal in Apache Ivy - CVE-2026-26032

 

Path traversal in Apache Ivy - CVE-2026-26032

Published: August 24, 2026


Vulnerability identifier: #VU144731
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-26032
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to overwrite arbitrary files.

The vulnerability exists due to path traversal in PackagerResolver when processing module coordinates containing "../" sequences from ivy.xml files in a packager repository. A remote user can add or modify crafted coordinates to overwrite arbitrary files.

Exploitation requires access to a packager repository.


Affected software

Apache Ivy
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Basesystem Module
Development Tools Module
Fedora
apache-commons-compress
apache-ivy

How to mitigate CVE-2026-26032

Install security update from vendor's website.

Apache Ivy - update to 2.6.0
apache-commons-compress - update to 1.28.0-150200.3.19.1
apache-ivy - addressed in versions 2.6.0-2.fc43, 2.6.0-2.fc44
apache-ivy - update to 2.6.0-150200.3.12.1

External References

Related Security Bulletins