PT-2026-99764 · Google · Fuse-Archive

·

CVE-2026-87723

·

Published

2026-09-28

·

Updated

2026-09-28

CVSS v4.0

5.4

Medium

VectorAV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Google fuse-archive versions prior to 1.24
Description An attacker can hijack the execution pathway by prepending a directory to the PATH environment variable or by writing a malicious binary to a writable directory that appears in the PATH. This allows for the execution of arbitrary local code using the security context of the user running the fuse-archive process. This issue is an Untrusted Search Path, which occurs when an application uses an external environment variable to locate an executable without properly validating the search path.
Recommendations Update to version 1.24.

Fix

Untrusted Search Path

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-87723

Affected Products

Fuse-Archive