CVE-2026-24049Patch(wheel_project / wheel)

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch wheel_project wheel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vulnerable to file permission modification through mishandling of file permissions after extraction. The logic blindly trusts the filename from the archive header for the chmod operation, even though the extraction process itself might have sanitized the path. Attackers can craft a malicious wheel file that, when unpacked, changes the permissions of critical system files (e.g., /etc/passwd, SSH keys, config files), allowing for Privilege Escalation or arbitrary code execution by modifying now-writable scripts. This issue has been fixed in version 0.46.2.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-732

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wheel

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 2 signals
  • Peaked 1d ago at 2 mentions (2026-02-01); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Products
wheel

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-01: 2Mentions · 2026-02-03: 1Patch / Workaround · 2026-02-01: 2Patch / Workaround · 2026-02-03: 1Technical Details · 2026-02-01: 202-0102-03
Signal classification1 categories
Patch
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-012
Patch2
2026-02-031
Patch1
Full discourse3 posts
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Just published a detailed analysis on the critical #openSUSE Leap 16.0 patch for CVE-2026-24049. This isn't just another bug fix. Read more: 👉 https://tinyurl.com/4b5ebsx6 #Security https://t.co/Lj1uhqXuKX

    Post summary

    The tweet announces a detailed analysis of the critical patch for CVE‑2026‑24049 on openSUSE Leap 16.0, emphasizing its importance without providing exploit details.

    0000038
    1.3K followersView on X
  • ThreatCluster@threatcluster
    Patch

    CVE-2026-24049 patched in Python wheel manipulation tools affecting Spyder 43 flask-bundle and Ubuntu 22 python-package. Admins should update CLI wheel tooling promptly. #Vulnerability https://threatcluster.io/cluster/security-vulnerability-in-python-wheel-manipulation-tools-ad-bd38b921

    Post summary

    The post announces that CVE-2026‑24049 has been patched in Python wheel manipulation tools impacting Spyder 43 and Ubuntu 22, and urges administrators to update their CLI wheel tooling to mitigate the issue.

    0000070
    80 followersView on X
  • ThreatCluster@threatcluster
    Patch

    Fedora 42 and 43 fix critical privilege escalation in mingw-python-wheel, CVE-2026-24049, with version 0.46.3 released January 22, 2026 by Sandro Mani. Users should update promptly. https://threatcluster.io/cluster/fedora-42-and-43-mingw-python-wheel-critical-privilege-escal-4371530b

    Post summary

    Fedora 42 and 43 now contain a patch for CVE-2026-24049, a privilege escalation flaw in mingw-python-wheel. Users are urged to update to the latest 0.46.3 release to mitigate the issue.

    0000059
    80 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwheel_projectwheel-python-

Explore more