Out-of-Bounds Heap Write in WinRAR Product by RARLab
CVE-2026-14191

7.8HIGH

Key Information:

Vendor

Rarlab

Status
Vendor
CVE Published:
1 July 2026

Badges

📈 Score: 1,710👾 Exploit Exists🟡 Public PoC📰 News Worthy

What is CVE-2026-14191?

CVE-2026-14191 is a vulnerability found in the WinRAR software, developed by RARLab, which is widely used for file compression and decompression. Specifically, this vulnerability is categorized as an out-of-bounds heap write located within the RAR5 recovery-volume parser. It arises due to improper validation of user input when processing a set of recovery volume files, leading to a scenario where an attacker can write data beyond the intended limits of allocated memory. If exploited, this vulnerability could enable an attacker to corrupt adjacent heap objects, potentially leading to severe consequences such as system crashes or unauthorized code execution.

The vulnerability arises when an attacker crafts a set of recovery volumes that are processed by the WinRAR application. By manipulating the inputs in such a way that they exploit the way sizes are calculated for the recovery items, an attacker can gain control over certain memory allocations. The exploitation requires user interaction, as the victim would need to execute recovery or extraction operations on the manipulated files.

Potential impact of CVE-2026-14191

  1. Remote Code Execution: Exploiting this vulnerability can allow attackers to gain control over the target system by executing arbitrary code, potentially leading to full system compromise.

  2. Data Corruption: The out-of-bounds write could corrupt critical data in memory, leading to unpredictable application behavior, data loss, or system crashes, which can disrupt business operations.

  3. Increased Attack Surface: Organizations using affected versions of WinRAR may be at heightened risk as the vulnerability could be combined with other exploits, leading to more sophisticated and damaging attacks such as further vulnerabilities being chained together for greater effect.

Affected Version(s)

RAR Windows 0 < 7.23

UnRAR Windows 0 <= 7.21

UnRAR.dll Windows 0 < 7.23

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

News Articles

WinRAR 7.23 Fixes Heap Overflow Vulnerability that Leads to Application Crashes - IT Security News

WinRAR 7.23 addresses a newly disclosed heap overflow vulnerability in the RAR5 recovery volume processing code, tracked as CVE-2026-14191. Closing a memory-corruption flaw that could be triggered by malicious recovery volume (.rev) data and potentially lead to application crashes or…Read more →

2 weeks ago

WinRAR 7.23 Fixes Heap Overflow Vulnerability that Leads to Application Crashes

WinRAR 7.23 addresses a newly disclosed heap overflow vulnerability in the RAR5 recovery volume processing code, tracked as CVE-2026-14191.

2 weeks ago

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • 📰

    First article discovered by Cybersecuritynews

  • Vulnerability published

  • Vulnerability Reserved

Credit

Arjun Basnet from Securin
.