PT-2026-60263 · Apache · Apache Ivy

·

CVE-2026-26032

·

Published

2026-07-15

·

Updated

2026-07-23

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Apache Ivy versions 2.0.0 through 2.5.3
Description The PackagerResolver in Apache Ivy allows the downloading and repackaging of online artifacts based on a packager.xml file. This process uses an Ant script stored in a subdirectory of the buildRoot directory, with the path determined by module coordinates such as organization, name, or version. If these coordinates contain ../ sequences, a path traversal occurs, allowing an attacker to break out of the buildRoot directory and overwrite files. Exploitation requires the attacker to have access to a packager repository to modify coordinates within ivy.xml files.
Recommendations Upgrade to Ivy 2.6.0.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-26032
OPENSUSE-SU-2026:11326-1
OPENSUSE-SU-2026:21424-1
SUSE-SU-2026:22858-1
SUSE-SU-2026:3225-1

Affected Products

Apache Ivy