CVE-2026-54550
Last modified
CVE-2026-54550 is a high-severity vulnerability rated 7.4/10 on the CVSS scale. IzPack is a widely used tool for packaging applications on the Java platform as cross-platform installers. In 5.2.6 and earlier, UnpackerBase.unpack() in izpack-installer/src/main/java/com/izforge/izpack/installer/unpacker/UnpackerBase.java obtains an attacker-controlled PackFile targetPath, passes it through IoHelper.translatePath(), which only converts separators, and constructs a File without normalizing parent-directory segments or enforcing destination containment. EPSS estimates a 0.38% chance of exploitation in the next 30 days.
Description
IzPack is a widely used tool for packaging applications on the Java platform as cross-platform installers. In 5.2.6 and earlier, UnpackerBase.unpack() in izpack-installer/src/main/java/com/izforge/izpack/installer/unpacker/UnpackerBase.java obtains an attacker-controlled PackFile targetPath, passes it through IoHelper.translatePath(), which only converts separators, and constructs a File without normalizing parent-directory segments or enforcing destination containment. A malicious installer pack entry containing ../ sequences can therefore write outside the intended installation directory to startup folders, executable search paths, or other locations accessible with the victim's privileges when the victim runs the installer.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| izpack | izpack | <= 5.2.6 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-54550?
How severe is CVE-2026-54550?
How do I fix CVE-2026-54550?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-54545wakaru is a JavaScript decompiler and unminifier toolkit. Fr…7.1
- CVE-2026-54546CloudTAK is a browser-based Common Operating Picture and sit…5
- CVE-2026-54547Meta Ads MCP is a Model Context Protocol (MCP) server that l…7.4
- CVE-2026-54548kas is a setup tool for bitbake based projects. Prior to 5.4…3.3
- CVE-2026-54549Meta Ads MCP is a Model Context Protocol (MCP) server that l…8.3
- CVE-2026-5455A vulnerability was determined in Dialogue App up to 4.3.2 o…3.3
- CVE-2026-54551WireGuard Portal, or wg-portal, is a web-based configuration…4.3
- CVE-2026-54552sh provides Python process launching. Prior to 2.2.4, the _u…7.9
- CVE-2026-54553Starlette-Admin is a fast, beautiful and extensible administ…5.4
- CVE-2026-54555rtk filters and compresses command outputs before they reach…7.8
- CVE-2026-54556Http4s is a Scala interface for HTTP services. Prior to 0.23…8.2
- CVE-2026-54557mise manages dev tools like node, python, cmake, and terrafo…5.5
Are you affected by CVE-2026-54550?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
