Path Traversal Vulnerability in libzypp Component of openSUSE Releases
CVE-2026-25707

8.8HIGH

Key Information:

Vendor

Suse

Status
Vendor
CVE Published:
29 June 2026

What is CVE-2026-25707?

A path traversal vulnerability exists in the libzypp package, which handles repository metadata. This flaw can be exploited by remote attackers through the manipulation of repository inputs, allowing them to overwrite files on an affected system. Such an exploit could lead to denial of service or unauthorized privilege escalation, threatening the integrity and availability of the affected systems.

Affected Version(s)

libzypp 0 < 17.38.10

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael Andres of SUSE
.