CVE-2026-25707Disclosure(opensuse / libzypp)

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch opensuse libzypp systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by remote attackers supplying repositories to overwrite files on the system, leading to denial of service or privilege escalation.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-23

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • libzypp

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
libzypp

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-06-29: 2Patch / Workaround · 2026-06-29: 1Technical Details · 2026-06-29: 206-29
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets3 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25707 Relative Path Traversal in libzypp Before 17.38.10 Enables File O... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25707 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The post announces a previously undisclosed relative path traversal vulnerability in libzypp before version 17.38.10, providing a link to further details.

    00010158
    4.1K followersView on X
  • ADK Cyber@ADKCyber
    Patch

    CVE-2026-25707 (CVSS 8.8): relative path traversal in libzypp < 17.38.10 allows file overwrites via malicious repos. Update SUSE systems. https://nvd.nist.gov/vuln/detail/CVE-2026-25707 via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability #AI #MachineLearning https://t.co/WAh86uZGY0

    Post summary

    CVE‑2026‑25707 is a high‑severity relative path traversal issue in libzypp affecting SUSE systems, permitting file overwrites through malicious repositories. Users are advised to update their systems to mitigate the vulnerability.

    0000037
    92 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopensuselibzypp---

Explore more