Junglewise Threat Intelligence

CVE-2026-14266: 7-Zip heap overflow in XZ decompression

CVE-2026-14266 · Severity: high · CVSS 7 · Published 2026-07-29

Technologies: 7-Zip. Vendors: 7-Zip.

Executive brief

7-Zip is a popular file compression and archiving utility used to manage various file formats. A security flaw in how it handles XZ-compressed files could allow an attacker to take control of a user's computer if the user is tricked into opening a specially crafted malicious file. This could lead to unauthorized access to personal data or the installation of harmful software.

Technical details

A heap-based buffer overflow vulnerability (CWE-122) exists in 7-Zip within the processing of XZ chunked data. The flaw is triggered during the decompression of specially crafted XZ-compressed data, leading to memory corruption. While categorized with a local attack vector in CVSS, the vulnerability is exploitable if a user opens a malicious file or visits a malicious page (User Interaction required). Successful exploitation allows an attacker to execute arbitrary code in the context of the current process. The issue is fixed in version 26.02.

Affected products

  • 7-Zip 7-Zip 26.01

Timeline

  • 2026-06-05: other: Vulnerability reported to vendor
  • 2026-07-15: advisory: Coordinated public release of advisory by ZDI
  • 2026-07-15: patched: Fixed in version 26.02
  • 2026-07-29: disclosed: NVD publication date

References

Related threats