CVE-2026-44941Disclosure(opensuse / libzypp)

MEDIUMCVSS 8.8 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch opensuse libzypp systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A relative path traversal in the "keyhint" option in repomd.xml parsing of libzypp before 17.38.12 can be used by attackers able to supply a malicious repository to inject or overwrite files in the target system as root.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-23

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • libzypp

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-07-02); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
libzypp

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-07-02: 2Mentions · 2026-07-03: 1Mentions · 2026-07-13: 1Active Exploitation · 2026-07-13: 1Patch / Workaround · 2026-07-03: 1Technical Details · 2026-07-02: 2Technical Details · 2026-07-03: 1Technical Details · 2026-07-13: 107-0207-0307-13
Signal classification3 categories
Disclosure
250.0%
Patch
125.0%
Active Exploitation
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-07-022
Disclosure2
2026-07-031
Patch1
2026-07-131
Active Exploitation1
Full discourse4 posts
  • CyStack@CyStackSecurity
    Active Exploitation

    CVE-2026-44941: Path traversal in libzypp, the core package manager of SUSE Linux and openSUSE. Run zypper refresh with a malicious repo. Write arbitrary files as root. Full RCE. Millions of servers affected. Found by Trung Nguyễn from CyStack. Details at https://cystack.net/disclosures #CyStack #CyberSecurity #Vulnerability #RCE #OpenSUSE #SUSE #openSUSE #Linux #SupplyChain #InfoSec

    Post summary

    CVE‑2026‑44941 is a path traversal flaw in libzypp that allows an attacker to gain root RCE and has reportedly affected millions of SUSE/OpenSUSE servers; details are available from the CyStack disclosure.

    0001079
    3.7K followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨High - libzypp Path Traversal in repomd.xml keyhint Parsing (CVE-2026-44941) libzypp - the ZYpp package-management library behind zypper and YaST on SUSE/openSUSE - mishandles the "keyhint" option when parsing a repository's repomd.xml. A relative path traversal in that field lets an attacker who can supply a malicious repository write outside the intended path. Because package operations run as root, this allows injecting or overwriting arbitrary files on the target system as root, leading to system compromise. Exploitation requires the target to use the attacker's repository (an admin adding/refreshing it), but the payoff is root-level file write. 👉Upgrade libzypp to 17.38.12.

    Post summary

    CVE‑2026‑44941 is a root‑privileged path traversal in libzypp’s keyhint handling that allows arbitrary file overwrites; upgrading to libzypp 17.38.12 mitigates the vulnerability.

    0000076
    236 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-44941 A relative path traversal in the "keyhint" option in repomd.xml parsing of libzypp before 17.38.12 can be used by attackers able to supply a malicious repository to i… https://www.cve.org/CVERecord?id=CVE-2026-44941 ----- Traducción: CVE-2026-44941 Una… http://infoflow.cloud`

    Post summary

    This post announces CVE-2026-44941, a relative path traversal vulnerability in libzypp prior to version 17.38.12, with no proof‑of‑concept, exploit, or patch details provided.

    0000034
    91 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-44941 A relative path traversal in the "keyhint" option in repomd.xml parsing of libzypp before 17.38.12 can be used by attackers able to supply a malicious repository to i… https://www.cve.org/CVERecord?id=CVE-2026-44941

    Post summary

    CVE-2026-44941 describes a relative path traversal vulnerability in libzypp’s repomd.xml parsing that can be exploited by attackers who supply a malicious repository; no exploit code, patches, or active usage reports are mentioned.

    00000826
    57.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopensuselibzypp---

Explore more