Out-of-Bounds Write Vulnerability in PeaZip by PeaZip Developers
CVE-2026-102514

8.4HIGH

Key Information:

Vendor

Peazip

Status
Vendor
CVE Published:
1 October 2026

What is CVE-2026-102514?

An out-of-bounds write vulnerability has been identified in the PeaZip archive extraction routine. This flaw allows an attacker to manipulate a specially crafted .pea archive, potentially allowing for arbitrary code execution when the victim decompresses it. The vulnerability arises from an improper check on the size of the compressed block, leading to unvalidated memory access. As a result, an attacker can exploit the application to overwrite critical memory areas, leading to memory corruption and denial-of-service conditions across different platforms, including Windows, macOS, Linux, and BSD. Users are encouraged to update to the latest version of PeaZip to mitigate the risks associated with this vulnerability.

Affected Version(s)

PeaZip Windows 0 < 11.3.0

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

julichaan
c4sh3r
Dario Rivas Quero
Secur0 CNA
.