Threat Advisory

adm-zip Flaw Lets Attackers Preserve SUID/SGID Bits from Untrusted ZIPs

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-102282 with a CVSS score of 7.1 is a CWE-732 vulnerability in adm-zip that lets attackers preserve SUID/SGID bits from untrusted ZIPs, resulting in local privilege escalation when extraction runs as root. Affected versions include <= 0.6.0. The flaw occurs due to the tool applying Unix permission bits directly from a zip entry without filtering bits. An attacker can craft a zip with a setuid binary that preserves its mode, leading to a root-owned setuid file being executed later by an unprivileged user. This vulnerability impacts applications and pipelines extracting untrusted archives while running as root, but default-usage deployments are not affected.

RECOMMENDATION:

We recommend you to update adm-zip to version 0.6.1.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-102282 with a CVSS score of 7.1 is a CWE-732 vulnerability in adm-zip that lets attackers preserve SUID/SGID bits from untrusted ZIPs, resulting in local privilege escalation when extraction runs as root. Affected versions include <= 0.6.0. The flaw occurs due to the tool applying Unix permission bits directly from a zip entry without filtering bits. An attacker can craft a zip with a setuid binary that preserves its mode, leading to a root-owned setuid file being executed later by an unprivileged user. This vulnerability impacts applications and pipelines extracting untrusted archives while running as root, but default-usage deployments are not affected.

RECOMMENDATION:

We recommend you to update adm-zip to version 0.6.1.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu