CVE-2026-3223Disclosure(google / web_designer)

LOWCVSS 7.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Arbitrary file write & potential privilege escalation exploiting zip slip vulnerability in Google Web Designer.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • web_designer

Threat summary

  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-02-27); latest day: 2
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
web_designer

1 version affected across 1 product

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-02-27: 2Mentions · 2026-03-02: 1Mentions · 2026-03-03: 2Technical Details · 2026-02-27: 2Technical Details · 2026-03-02: 1Technical Details · 2026-03-03: 102-2703-0203-03
Signal classification2 categories
Disclosure
360.0%
General
240.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-272
Disclosure2
2026-03-021
Disclosure1
2026-03-032
General2
Full discourse5 posts
  • dbugs@ptdbugs
    Disclosure

    Zip Slip leading to Arbitrary File Write and Privilege Escalation in Google Web Designer CVE: CVE-2026-3223 Vendor: Google Product: Web Designer CVSS: 8.4 Credits: n/a Description: Arbitrary file write & potential privilege escalation exploiting zip slip vulnerability in Google Web Designer. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-3223 • https://bughunters.google.com/reports/vrp/FJMQGy8oo

    Post summary

    A new CVE-2026-3223 zip slip vulnerability in Google Web Designer allows arbitrary file write and potential privilege escalation, with a CVSS score of 8.4, but no PoC, exploit, or patch details are provided.

    118079485.9K
    551 followersView on X
  • VulnTracker@vuln_tracker
    General

    Another reminder that zip slip isn't going anywhere 📁 CVE-2026-3223 in Google Web Designer (CVSS 8.4) shows even major vendors still struggle with archive handling. How many zip slip vulns have you seen this year? The pattern keeps repeating... We also collected all the information you need about this CVE here: http://vulntracker.io/cves/CVE-2026-3223

    Post summary

    The post highlights CVE-2026-3223, a zip slip vulnerability in Google Web Designer with a CVSS score of 8.4, and points to a resource for more details, but provides no PoC, exploit, patch, or evidence of active exploitation.

    00001100
    365 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-21513 2 - CVE-2025-14500 3 - CVE-2026-21236 4 - CVE-2026-2441 5 - CVE-2026-3223 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post simply lists five trending CVEs without providing any technical details, PoC, or exploitation information.

    00010166
    1.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3223 Arbitrary File Write and Privilege Escalation in Google Web Designer via Zip Slip https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3223

    Post summary

    CVE-2026-3223 is disclosed as an arbitrary file write and privilege escalation vulnerability in Google Web Designer via Zip Slip, with no PoC, exploit, patch, or active exploitation details provided.

    0000049
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3223 Arbitrary file write & potential privilege escalation exploiting zip slip vulnerability in Google Web Designer. https://www.cve.org/CVERecord?id=CVE-2026-3223

    Post summary

    The text announces CVE‑2026‑3223 as a zip slip vulnerability in Google Web Designer that allows arbitrary file writes and potential privilege escalation, with no PoC, exploit, or patch information provided.

    0000077
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgoogleweb_designer14.2.2.0--

Explore more