Path Traversal Vulnerability in libzypp Component of openSUSE Releases
CVE-2026-25707
8.8HIGH
What is CVE-2026-25707?
A path traversal vulnerability exists in the libzypp package, which handles repository metadata. This flaw can be exploited by remote attackers through the manipulation of repository inputs, allowing them to overwrite files on an affected system. Such an exploit could lead to denial of service or unauthorized privilege escalation, threatening the integrity and availability of the affected systems.
Affected Version(s)
libzypp 0 < 17.38.10