// For flags

CVE-2026-28208

Junrar has arbitrary file write due to backslash path traversal bypass in LocalFolderExtractor on Linux/Unix

Severity Score

5.9
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Attend
*SSVC
Descriptions

Junrar is an open source java RAR archive library. Prior to version 7.5.8, a backslash path traversal vulnerability in `LocalFolderExtractor` allows an attacker to write arbitrary files with attacker-controlled content anywhere on the filesystem when a crafted RAR archive is extracted on Linux/Unix. This can often lead to remote code execution (e.g., overwriting shell profiles, source code, cron jobs, etc). Version 7.5.8 has a fix for the issue.

Junrar es una biblioteca de archivo RAR de Java de código abierto. Antes de la versión 7.5.8, una vulnerabilidad de salto de ruta con barra invertida en 'LocalFolderExtractor' permite a un atacante escribir archivos arbitrarios con contenido controlado por el atacante en cualquier lugar del sistema de archivos cuando se extrae un archivo RAR manipulado en Linux/Unix. Esto a menudo puede conducir a la ejecución remota de código (por ejemplo, sobrescribiendo perfiles de shell, código fuente, tareas cron, etc.). La versión 7.5.8 tiene una solución para el problema.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:Attend
Exploitation
Poc
Automatable
No
Tech. Impact
Total
* Organization's Worst-case Scenario
Timeline
  • 2026-02-25 CVE Reserved
  • 2026-02-26 CVE Published
  • 2026-03-02 CVE Updated
  • 2026-03-02 First Exploit
  • 2026-04-09 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Junrar Project
Search vendor "Junrar Project"
Junrar
Search vendor "Junrar Project" for product "Junrar"
< 7.5.8
Search vendor "Junrar Project" for product "Junrar" and version " < 7.5.8"
-
Affected