PT-2026-60346 · 7 Zip · 7-Zip
CVE-2026-14266
·
Published
2026-06-26
·
Updated
2026-07-23
CVSS v2.0
6.2
Medium
| Vector | AV:L/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
7-Zip versions prior to 26.02
Description
A heap-based buffer overflow exists in the XZ decompression path when processing specially crafted XZ chunked data. The issue occurs within the
MixCoder Code() function in the XzDec.c file, where the software fails to properly subtract already filled space from the full buffer size, leading to an out-of-bounds write. An attacker can exploit this by enticing a user to open a malicious archive or visit a webpage that delivers the payload. Successful exploitation allows for arbitrary code execution in the context of the current process, inheriting the privileges held by 7-Zip. On Windows, this typically corresponds to a filtered standard-user token unless the application was started with elevated privileges.Recommendations
Update to version 26.02 or newer.
Exploit
Fix
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
7-Zip