PT-2026-53084 · 7 Zip+1 · 7-Zip

·

CVE-2026-58052

·

Published

2026-06-23

·

Updated

2026-08-07

CVSS v4.0

4.8

Medium

VectorAV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions 7-Zip for Windows versions prior to 26.02
Description 7-Zip fails to preserve the Mark-of-the-Web (MotW) when extracting a specially crafted RAR5 archive. The software uses a guard to suppress archive-supplied Zone.Identifier streams, but it only matches the exact name Zone.Identifier. An attacker can use a RAR5 STM (Stream Extension) record named :Zone.Identifier:$DATA, which NTFS canonicalizes to the same stream, effectively overwriting the Internet-zone marker with ZoneId=0. Additionally, a second STM record named ::$DATA can overwrite the extracted file's default data stream. This allows an attacker to bypass SmartScreen and MotW warnings and spoof file content.
Recommendations Update 7-Zip for Windows to a version newer than 26.02.

Exploit

Fix

DoS

Protection Mechanism Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-08978
CVE-2026-58052
ECHO-A273-202B-9560
JLSEC-2026-1169

Affected Products

7-Zip