← back
CVE-2026-77113mediumCWE-23

Path Traversal Vulnerability in apport-unpack

33Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 6.7epss 0.2%
from disclosure to weapon0 days
Published on NVDAug 20
1st PoCAug 18
exploitation probability
0.2%top 85% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Path traversal in apport-unpack in Canonical Apport before 2.36.0, 2.34.2, and 2.28.4 on Linux allows an attacker to create or overwrite arbitrary files with the privileges of the executing user via an attacker controlled key names in crash report files.
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Affected products
Canonical · Apport
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.