CVE-2026-88069
Awaiting Analysis Awaiting Analysis - Queue

Path Traversal in Pandora Archive Extraction Worker

Vulnerability report for CVE-2026-88069, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-10

Assigner: CIRCL

Description

Pandora contains a path traversal vulnerability in its archive extraction worker. When processing a specially crafted archive or disk image, attacker-controlled file paths could be used without ensuring that the resulting destination remained within the intended extraction directory. An attacker able to submit a malicious file for analysis could use path traversal sequences or crafted paths to cause extracted content to be written outside the designated extraction directory, potentially overwriting files accessible to the Pandora worker process. Successful exploitation could result in unauthorized modification of application or system files, denial of service, and potentially further compromise depending on the permissions of the Pandora process and the files that can be overwritten. The vulnerability is addressed by resolving each extraction destination path before writing and verifying that it remains below the expected extraction directory. Extraction attempts resolving outside this directory are rejected and reported as path traversal attempts.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-10
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-29
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
pandora_analysis pandora *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Pandora has a path traversal vulnerability in its archive extraction worker. Attackers can submit malicious archives or disk images with crafted file paths that bypass intended directory restrictions. This allows writing files outside the designated extraction folder, potentially overwriting system or application files.

Detection Guidance

To detect this vulnerability, monitor for unusual file writes outside expected directories during archive extraction. Check logs for path traversal attempts like '../' or absolute paths in filenames. Use tools like 'find' to scan for recently modified files outside extraction folders. Example command: find / -type f -mtime -1 -exec ls -l {} \; | grep -E '(\.\./|/etc/|/usr/)'

Impact Analysis

An attacker could exploit this to overwrite critical files, causing denial of service or further system compromise. The impact depends on the permissions of the Pandora process and which files can be overwritten. Successful exploitation may lead to unauthorized file modifications or system instability.

Compliance Impact

This vulnerability could lead to unauthorized file modifications or overwrites, which may result in unauthorized access to sensitive data. This could violate GDPR's integrity and confidentiality principles or HIPAA's safeguards for protected health information if exploited.

Mitigation Strategies

Update Pandora to the latest version that includes path traversal fixes. Ensure the Pandora worker process runs with minimal permissions. Monitor extraction logs for path traversal attempts or unauthorized file writes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-88069. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart