CVE-2026-20217: a vulnerability chain in ZendTo and ClamAV

CVE-2026-20217: a vulnerability chain in ZendTo and ClamAV
This article examines the vulnerability CVE-2026-20217, involving an exploitation chain in the ZendTo application and the ClamAV antivirus engine, where the mechanism for scanning uploaded files through the antivirus daemon serves as an entry point for remote code execution (RCE). The primary attack vector relies on a publicly accessible file upload workflow that passes user-supplied data to ClamAV to analyze archives and nested objects.
The key issue is ClamAV's improper handling of PE/archive structures, which allows an attacker to use a specially crafted file to corrupt the heap and subsequently gain control of execution. This results in code execution in the context of the ClamAV service (clamav user) with a potential subsequent escalation to a higher privilege level, depending on the system configuration.
Vulnerabilities
7.8
CVE-2026-20217
Researchers
Tianchu Chen
Vendors
Zendto
Clamav
Products
Clamav
Zendto