


Perceptive Security
SOC/SIEM Consultancy

IzPack is a widely used tool for packaging applications on the Java platform as cross-platform installers. In 5.2.6 and earlier, UnpackerBase.unpack() in izpack…
Published:
26 augustus 2026 om 00:00:00
Alert date:
26 augustus 2026 om 18:17:38
Source:
nvd.nist.gov
Supply Chain & Dependencies, Enterprise Applications
IzPack versions 5.2.6 and earlier contain a path traversal vulnerability in the UnpackerBase.unpack() method. The vulnerability arises because attacker-controlled PackFile targetPath values are passed through IoHelper.translatePath(), which only converts path separators without normalizing parent-directory segments or enforcing destination containment. This allows a malicious installer pack entry containing ../ sequences to write files outside the intended installation directory. Exploitation could result in files being written to startup folders, executable search paths, or other sensitive locations accessible with the victim's privileges. The attack is triggered when a victim runs a maliciously crafted installer. Fixes have been committed to the IzPack GitHub repository and a security advisory has been published. Users are advised to update to a patched version as soon as available.
Technical details
Mitigation steps:
Affected products:
IzPack 5.2.6 and earlier
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-54550
https://github.com/izpack/izpack/commit/4233ba38d0f1825f9cf3e0204e5261a5498e29d8
https://github.com/izpack/izpack/commit/8b7c6792c4fe85e3b1759c106aae39b904848466
https://github.com/izpack/izpack/pull/1193
https://github.com/izpack/izpack/security/advisories/GHSA-f63g-88cj-hjf9
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
