CVE-2026-77113
MediumPublished
Path Traversal Vulnerability in apport-unpack
- Published
- Aug 20, 2026
- Updated
- Aug 21, 2026
- Assigning CNA
- canonical
- Evidence observed
- Aug 24, 2026
Primary CVSS
6.7/ 10Medium
cvelist · CVSS 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:NSummary
Path traversal in apport-unpack in Canonical Apport before 2.36.0, 2.34.2, and 2.28.4 on Linux allows an attacker to create or overwrite arbitrary files with the privileges of the executing user via an attacker controlled key names in crash report files.
Sources
Technical write-up for CVE-2026-77113, a path traversal in Apport's apport-unpack where crafted report keys escape the extraction directory and write files outside the destination.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.