PT-2026-60346 · 7 Zip · 7-Zip

CVE-2026-14266

·

Published

2026-06-26

·

Updated

2026-07-23

CVSS v2.0

6.2

Medium

VectorAV:L/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions 7-Zip versions prior to 26.02
Description A heap-based buffer overflow exists in the XZ decompression path when processing specially crafted XZ chunked data. The issue occurs within the MixCoder Code() function in the XzDec.c file, where the software fails to properly subtract already filled space from the full buffer size, leading to an out-of-bounds write. An attacker can exploit this by enticing a user to open a malicious archive or visit a webpage that delivers the payload. Successful exploitation allows for arbitrary code execution in the context of the current process, inheriting the privileges held by 7-Zip. On Windows, this typically corresponds to a filtered standard-user token unless the application was started with elevated privileges.
Recommendations Update to version 26.02 or newer.

Exploit

Fix

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-10443
CVE-2026-14266
OPENSUSE-SU-2026:11319-1
ZDI-26-444

Affected Products

7-Zip