← back
CVE-2026-58052

7-Zip - Mark-of-the-Web Bypass via RAR5 Alternate Data Stream Name Collision

CVSS 4.8 MEDIUMEPSS 0.1%CWE-693
Vexday Risk Score
33Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 4.8EPSS 0.1%KEV nãoPoC públicaNuclei Metasploit Patch
Lifecycle
28 Jun 2026Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
7-Zip for Windows through 26.02 fails to preserve the Mark-of-the-Web when extracting a crafted RAR5 archive, because its guard that suppresses an archive-supplied Zone.Identifier stream matches the exact name 'Zone.Identifier' while a RAR5 STM record named ':Zone.Identifier:$DATA' is not matched and NTFS canonicalizes it to the same stream, overwriting the propagated Internet-zone marker with ZoneId=0. A second STM record named '::$DATA' overwrites the extracted file's default data stream, letting an attacker defeat SmartScreen/MotW warnings and spoof file content.
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Affected products
7-Zip · 7-Zip
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →