[CIVN-2026-0274] Multiple Vulnerabilities in 7-Zip

By Published On: May 29, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Multiple Vulnerabilities in 7-Zip




Indian – Computer Emergency Response Team (https://www.cert-in.org.in)




Severity Rating: HIGH




Software Affected




7-Zip versions prior to 26.01


Overview




Multiple vulnerabilities have been reported in 7-Zip, which could be exploited by an attacker to disclose sensitive information, cause denial of service conditions, perform arbitrary file write operations, and execute arbitrary code on the targeted system.




Target Audience:


All end-user organizations and individuals using affected versions of 7-Zip.




Risk Assessment:


High risk of sensitive information disclosure, arbitrary file write, arbitrary code execution, denial of service, and application crashes.


 


Impact Assessment:


Potential for unauthorized access to sensitive information, arbitrary file modification, arbitrary code execution, full system compromise and service disruption.




Description




7-Zip is an open-source file archiver utility used for creating, managing, and extracting compressed archives across various formats.




These vulnerabilities exist in 7-Zip due to improper handling of memory operations, insufficient bounds validation, use of uninitialized memory, integer overflow conditions, and inadequate path validation in multiple archive handlers and extraction routines.




Successful exploitation of these vulnerabilities could allow an attacker to disclose sensitive information, cause denial of service conditions, perform arbitrary file write operations, and execute arbitrary code on the targeted system.




Solution




Update to version 26.01 or later of 7-Zip




Vendor Information




7-Zip


https://7-zip.org/




References




 


https://securitylab.github.com/advisories/GHSL-2026-115_GHSL-2026-122_7-zip/


https://securitylab.github.com/advisories/GHSL-2026-140_7-Zip/




CVE Name


CVE-2026-48092


CVE-2026-48101


CVE-2026-48102


CVE-2026-48103


CVE-2026-48104


CVE-2026-48111


CVE-2026-48112


CVE-2026-48095








– – —




Thanks and Regards,


CERT-In




Incident Response Help Desk


e-mail: incident@cert-in.org.in


Phone: +91-11-22902657


Toll Free Number: 1800-11-4949


Toll Free Fax : 1800-11-6969


Web: http://www.cert-in.org.in


PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4


PGP Key information:


https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS




Postal address:


Indian Computer Emergency Response Team (CERT-In)


Ministry of Electronics and Information Technology


Government of India


Electronics Niketan


6, C.G.O. Complex


New Delhi-110 003


– –


—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmoZshQACgkQ3jCgcSdc

ys8ulA/6Am3gwNXF7ILr9NtOgqrkIEyvnxIikNxQCI2whUJmLzxMUAnPvzNjNDe9

rNHCxSuiOA5UohgmXetzSbxhC2zjxpn2QSGb2KgQLLUIJRF33+hvVHoUYkV3ujDv

x0aZE5BjzMsmQv6Ae0SG24EIGTfGn5Y873nZE40bi72xMmYRcbwEKIj2Hkmc7xUP

xrTKYjIUoianNVhDlVvqdAwHoes/0EnT91v4rHG8Ap7ptTNIStWqpbKl3H10P5lB

47oUiubpNeI4e4JMV0/wzp32N/ISz5WI5oUrurswB5cT6m3gAIpTm39f3BrsxVVl

2WiYWdb5Phc2E91CzNflN0c7Fnu0d+mca8nukgAJVaklHPgZhke7STIdtrd+Tch/

xg3DMok6litAq1MDBgbOcXX4QuNsV64TivNzqszyRFyb67S8bNqwNtEZq7CKlTrp

+yVRO3mqtxFZe4+O04Z/P8cWz4RBZHAYcQNnCVxn/wdNWCJqmXkcgcoLKnztQFls

hxGPV++yHH4tNmAE7gY7LGkpAUeKSX1YDBcx1qRrgE/M+41CC9+Sk797zjmGVxZb

PThGpuDXrSKIyHlzYFMChc4DsxbnececcO9Wl7fzoIeUMkwFYzKqzDcD7/o/t3tl

RwKuD38nDvcVCyc6fwg8wUuUrz9DBa51pHJREBW39uZCqy5nC38=

=Q5Xc

—–END PGP SIGNATURE—–

Share this article