← Vulnerability feed

Vulnerability record · CVE-2026-44941 · published 2 July 2026

CVE-2026-44941: Opensuse libzypp relative path traversal vulnerability

Opensuse · Libzypp

A relative path traversal in the "keyhint" option in repomd.xml parsing of libzypp before 17.38.12 can be used by attackers able to supply a malicious repository to inject or overwrite files in the target system as root.

8.8 CVSS 3.1 High EPSS 0.53% · top 57.2% CWE-23 · Relative path traversal
8.8CVSS 3.1 base score
0.53%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 1 tagged exploit
7 Jul 2026Last modified by NVD

Description

A relative path traversal in the "keyhint" option in repomd.xml parsing of libzypp before 17.38.12 can be used by attackers able to supply a malicious repository to inject or overwrite files in the target system as root.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-44941 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-9269Opensuse libzypp improper input validation vulnerabilityIn libzypp before August 2018 GPG keys attached to YUM repositories were not correctly pinned, allowing malicious repository mirrors to silently down…EPSS 2.2%8.8CVE-2026-25707Opensuse libzypp relative path traversal vulnerabilityA relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by remote attackers supplying repo…EPSS 0.60%8.1CVE-2017-7435Opensuse libzypp improper input validation vulnerabilityIn libzypp before 20170803 it was possible to add unsigned YUM repositories without warning to the user that could lead to man in the middle or malic…EPSS 1.8%8.1CVE-2017-7436Opensuse libzypp improper input validation vulnerabilityIn libzypp before 20170803 it was possible to retrieve unsigned packages without a warning to the user which could lead to man in the middle or malic…EPSS 1.8%7.8CVE-2018-7685Opensuse libzypp improper verification of cryptographic signature vulnerabilityThe decoupled download and installation steps in libzypp before 17.5.0 could lead to a corrupted RPM being left in the cache, where a later call woul…EPSS 0.29%3.3CVE-2019-18900Opensuse libzypp incorrect default permissions vulnerability: Incorrect Default Permissions vulnerability in libzypp of SUSE CaaS Platform 3.0, SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15 …EPSS 0.30%6.7CVE-2026-34926Trend Micro Apex One on-premise server directory traversal enables agent code injectionA relative path traversal (CWE-23) in the Apex One on-premise server lets an attacker who already holds administrative credentials on the server modi…KEVEPSS 0.54%analysed7.3CVE-2024-27199JetBrains TeamCity path traversal enables limited admin actionsJetBrains TeamCity before 2023.11.4 is vulnerable to relative path traversal that lets an unauthenticated remote party perform limited administrative…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2026-44941), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.