
[CIVN-2026-0274] Multiple Vulnerabilities in 7-Zip
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in 7-Zip
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: HIGH
Software Affected
7-Zip versions prior to 26.01
Overview
Multiple vulnerabilities have been reported in 7-Zip, which could be exploited by an attacker to disclose sensitive information, cause denial of service conditions, perform arbitrary file write operations, and execute arbitrary code on the targeted system.
Target Audience:
All end-user organizations and individuals using affected versions of 7-Zip.
Risk Assessment:
High risk of sensitive information disclosure, arbitrary file write, arbitrary code execution, denial of service, and application crashes.
Impact Assessment:
Potential for unauthorized access to sensitive information, arbitrary file modification, arbitrary code execution, full system compromise and service disruption.
Description
7-Zip is an open-source file archiver utility used for creating, managing, and extracting compressed archives across various formats.
These vulnerabilities exist in 7-Zip due to improper handling of memory operations, insufficient bounds validation, use of uninitialized memory, integer overflow conditions, and inadequate path validation in multiple archive handlers and extraction routines.
Successful exploitation of these vulnerabilities could allow an attacker to disclose sensitive information, cause denial of service conditions, perform arbitrary file write operations, and execute arbitrary code on the targeted system.
Solution
Update to version 26.01 or later of 7-Zip
Vendor Information
7-Zip
https://7-zip.org/
References
https://securitylab.github.com/advisories/GHSL-2026-115_GHSL-2026-122_7-zip/
https://securitylab.github.com/advisories/GHSL-2026-140_7-Zip/
CVE Name
CVE-2026-48092
CVE-2026-48101
CVE-2026-48102
CVE-2026-48103
CVE-2026-48104
CVE-2026-48111
CVE-2026-48112
CVE-2026-48095
– – —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
– –
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmoZshQACgkQ3jCgcSdc
ys8ulA/6Am3gwNXF7ILr9NtOgqrkIEyvnxIikNxQCI2whUJmLzxMUAnPvzNjNDe9
rNHCxSuiOA5UohgmXetzSbxhC2zjxpn2QSGb2KgQLLUIJRF33+hvVHoUYkV3ujDv
x0aZE5BjzMsmQv6Ae0SG24EIGTfGn5Y873nZE40bi72xMmYRcbwEKIj2Hkmc7xUP
xrTKYjIUoianNVhDlVvqdAwHoes/0EnT91v4rHG8Ap7ptTNIStWqpbKl3H10P5lB
47oUiubpNeI4e4JMV0/wzp32N/ISz5WI5oUrurswB5cT6m3gAIpTm39f3BrsxVVl
2WiYWdb5Phc2E91CzNflN0c7Fnu0d+mca8nukgAJVaklHPgZhke7STIdtrd+Tch/
xg3DMok6litAq1MDBgbOcXX4QuNsV64TivNzqszyRFyb67S8bNqwNtEZq7CKlTrp
+yVRO3mqtxFZe4+O04Z/P8cWz4RBZHAYcQNnCVxn/wdNWCJqmXkcgcoLKnztQFls
hxGPV++yHH4tNmAE7gY7LGkpAUeKSX1YDBcx1qRrgE/M+41CC9+Sk797zjmGVxZb
PThGpuDXrSKIyHlzYFMChc4DsxbnececcO9Wl7fzoIeUMkwFYzKqzDcD7/o/t3tl
RwKuD38nDvcVCyc6fwg8wUuUrz9DBa51pHJREBW39uZCqy5nC38=
=Q5Xc
—–END PGP SIGNATURE—–


