CVE-2026-14266
EUVD-2026-5042029.07.2026, 18:16
7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of XZ chunked data. Crafted XZ-compressed data can trigger an overflow of a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-30169.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| 7-zip | 7-zip | 𝑥 < 26.02 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Amazon Linux Releases
Amazon Package | |||
|---|---|---|---|
| 7zip |
| ||
| 7zip-debuginfo |
| ||
| 7zip-debugsource |
| ||
| 7zip-reduced |
| ||
| 7zip-reduced-debuginfo |
| ||
| 7zip-standalone |
| ||
| 7zip-standalone-all |
| ||
| 7zip-standalone-all-debuginfo |
| ||
| 7zip-standalone-debuginfo |
|
Vulnerability Media Exposure