Junglewise Threat Intelligence

CVE-2026-26157: BusyBox path traversal in archive extraction utilities

CVE-2026-26157 · Severity: high · CVSS 7 · Published 2026-02-11

Technologies: Siemens RUGGEDCOM RST2428P, Busybox, Siemens SINEC OS. Vendors: Siemens, Busybox.

Executive brief

BusyBox, a widely used suite of command-line utilities for embedded systems and Linux distributions, contains a flaw in how it handles compressed archives. An attacker can create a specially crafted archive file that, when opened by a user, writes files to locations outside of the intended folder. This could allow an attacker to overwrite critical system files, potentially leading to a full system takeover or service disruption.

Technical details

A path traversal vulnerability exists in the strip_unsafe_prefix() function within BusyBox's archive extraction utilities, including tar, unzip, rpm, ar, and dpkg. The flaw is caused by incomplete path sanitization that fails to properly detect and strip trailing '..' components in filenames (e.g., 'logs/data/..'). If a user extracts a malicious archive while the current working directory matches the target location, the utility may write files outside the intended directory. This can be leveraged to overwrite sensitive system files like shell configurations or cron jobs to achieve arbitrary code execution. The vulnerability affects BusyBox versions 1.36.1 and 1.37.0.

Affected products

  • BusyBox BusyBox 1.36.1, 1.37.0
  • Siemens SINEC OS before V4.0
  • Siemens RUGGEDCOM RST2428P before V4.0

Timeline

  • 2026-02-11: disclosed: Initial report by Red Hat
  • 2026-02-11: advisory: NVD entry published
  • 2026-05-05: patched: Red Hat released updated RPMs for Hardened Images
  • 2026-06-02: advisory: Siemens released advisory SSA-253495 for SINEC OS products

References

Related threats