🔐 CVE Alert

CVE-2026-77113

UNKNOWN 0.0

Path Traversal Vulnerability in apport-unpack

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Path traversal in apport-unpack in Canonical Apport before 2.36.0, 2.34.2, and 2.28.4 on Linux allows an attacker to create or overwrite arbitrary files with the privileges of the executing user via an attacker controlled key names in crash report files.

CWE CWE-23
Vendor canonical
Product apport
Ecosystems
Industries
Technology
Published Aug 20, 2026
Stay Ahead of the Next One

Get instant alerts for canonical apport

Be the first to know when new unknown vulnerabilities affecting canonical apport are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Canonical / Apport
0 < 2.36.0 0 < 2.34.2 0 < 2.28.4

References

NVD ↗ CVE.org ↗ EPSS Data ↗
launchpad.net: https://launchpad.net/bugs/2161697 github.com: https://github.com/canonical/apport/pull/646

Credits

Sakib Sarkar (0xROI)