LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-14947

Published
CVSS7.2
Severityhigh
WeaknessCWE-24
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Description

A high-privileged remote attacker can upload malicious ZIP archive containing directory traversal sequences such as ../ can escape the intended extraction directory and write files to arbitrary locations on the server, potentially achieve arbitrary code execution due to improper validation of archive entry paths before writing files to disk which could result in full system compromise.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-14947

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-14947.