Path Traversal Vulnerability in Canonical Apport on Linux Systems
CVE-2026-77113

6.7MEDIUM

Key Information:

Vendor

Canonical

Status
Vendor
CVE Published:
20 August 2026

What is CVE-2026-77113?

A path traversal vulnerability exists in the apport-unpack component of Canonical Apport prior to versions 2.36.0, 2.34.2, and 2.28.4 on Linux systems. This flaw allows attackers to exploit crash report files by using specially crafted key names, enabling them to create or overwrite arbitrary files with the privileges of the executing user. This poses significant risks, potentially leading to unauthorized access and manipulation of sensitive data.

Affected Version(s)

Apport Linux 0 < 2.36.0

Apport Linux 0 < 2.34.2

Apport Linux 0 < 2.28.4

References

CVSS V4

Score:
6.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sakib Sarkar (0xROI)
.