Path traversal in Apache Ivy - CVE-2026-26032
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote user to overwrite arbitrary files.
The vulnerability exists due to path traversal in PackagerResolver when processing module coordinates containing "../" sequences from ivy.xml files in a packager repository. A remote user can add or modify crafted coordinates to overwrite arbitrary files.
Exploitation requires access to a packager repository.
Affected software
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
Basesystem Module
Development Tools Module
Fedora
apache-commons-compress
apache-ivy
How to mitigate CVE-2026-26032
apache-commons-compress - update to 1.28.0-150200.3.19.1
apache-ivy - addressed in versions 2.6.0-2.fc43, 2.6.0-2.fc44
apache-ivy - update to 2.6.0-150200.3.12.1