SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-15028

LOW · CVSS 3.9 EPSS 0.20% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-10 · Last synced 2026-08-09

CyberRota Analysis

AI-Generated

A vulnerability in libarchive allows remote attackers to exploit a heap overflow by submitting a specially crafted tar archive, specifically targeting the parsing of a malformed PAX extended header. This could result in denial of service or potentially arbitrary code execution, compromising system availability and security. Organizations utilizing libarchive should prioritize patching this vulnerability to mitigate the associated risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit arbitrary code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-15028
Severity
LOW
CVSS
3.9
EPSS
0.20%

Original NVD Description

A flaw was found in libarchive. This vulnerability allows a remote attacker to trigger a heap overflow by providing a specially crafted tar archive. The issue occurs during the parsing of a PAX extended header containing a malformed SUN.holesdata sparse-file attribute. Successful exploitation could lead to a denial of service, making the system unavailable, or potentially allow for arbitrary code execution, giving the attacker control over the affected system.