ZDI-26-705: (0Day) BusyBox libarchive Symlink Directory Traversal Arbitrary File Creation Vulnerability
ZDI disclosed an unpatched symlink directory traversal flaw (CVE-2026-92205, CVSS 6.1) in BusyBox libarchive enabling arbitrary file creation.
ZDI-26-705 details an arbitrary file creation vulnerability in BusyBox's libarchive component caused by symlink directory traversal. Remote exploitation requires user interaction, such as visiting a malicious page or opening a malicious file. The flaw is rated CVSS 6.1, tracked as CVE-2026-92205, and published as a 0day advisory.
- Unpatched symlink directory traversal in BusyBox libarchive
- Allows arbitrary file creation on affected systems
- Requires user interaction to exploit
- Assigned CVE-2026-92205 with CVSS 6.1
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-92205 | NVD description · AI analysis pending | — | — | — | — | — |
This vulnerability allows remote attackers to create arbitrary files on affected installations of BusyBox. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-92205.
This source does not provide full text. Read it at zerodayinitiative.com.