PT-2026-52538 · Rancher · K3S

·

CVE-2026-54250

·

Published

2026-06-25

·

Updated

2026-07-30

CVSS v3.1

5.8

Medium

VectorAV:L/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions K3s versions prior to 1.35.3+k3s1 K3s versions prior to 1.34.6+k3s1 K3s versions prior to 1.33.10+k3s1
Description A path traversal issue exists in the etcd snapshot decompression functionality. This occurs when an administrator restores a compressed etcd snapshot containing a zip file with maliciously crafted archive member names, allowing files to be written to arbitrary locations on the filesystem.
Recommendations Update to version 1.35.3+k3s1. Update to version 1.34.6+k3s1. Update to version 1.33.10+k3s1.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54250
GHSA-JXR7-MQHW-9P98
GO-2026-5973
OPENSUSE-SU-2026:21483-1

Affected Products

K3S