PT-2026-80731 · Velero · Velero

·

CVE-2026-32637

·

Published

2026-08-20

·

Updated

2026-09-04

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Velero versions prior to 1.18.1
Description An attacker who gains control of the backup object-storage backend can upload a malicious backup tarball. This tarball can contain parent-directory paths that allow files to escape the intended extraction directory during the restore process, enabling the overwriting of sensitive files within the Velero pod filesystem.
Recommendations Update to version 1.18.1.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-32637
GHSA-J2G6-362Q-6QC6
GO-2026-6259
OPENSUSE-SU-2026:21761-1

Affected Products

Velero