[0day-rubbish] FME Flow 2026.2 Zip-Slip arbitrary file write to code execution as LocalSystem (8.8)
FME Flow 2026.2 has a Zip-Slip flaw that can write arbitrary files and execute code as LocalSystem.
Researchers disclosed a Zip-Slip path traversal (CWE-22) in Safe Software FME Flow 2026.2 build 26333. Archive extraction in StoreManager.extract() uses zip entry names without normalizing parent-directory sequences, allowing arbitrary file writes. The write can lead to code execution as LocalSystem and is scored 8.8. No CVE or observed exploitation is stated.
52