---
id: CVE-2026-26158
title: A flaw was found in BusyBox
summary: >-
  A flaw was found in BusyBox. This vulnerability allows an attacker to modify
  files outside of the intended extraction directory by crafting a malicious tar
  archive containing unvalidated hardlink or symlink entries. If the tar archive
  is…
severity: high
cvss: 7
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-73
  - CWE-73
published: '2026-02-11'
updated: '2026-06-30'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-26158'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:13831'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2026-26158'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2439040'
    label: secalert@redhat.com
  - url: >-
      https://git.busybox.net/busybox/commit/archival?id=3fb6b31c716669e12f75a2accd31bb7685b1a1cb
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:13831'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/security/cve/CVE-2026-26158'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2439040'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-253495.html'
    label: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-26158.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
tags:
  - nvd
epss: 0.00171
epssPercentile: 0.05718
ingestedAt: '2026-07-03T18:53:52.210Z'
---

## Overview

A flaw was found in BusyBox. This vulnerability allows an attacker to modify files outside of the intended extraction directory by crafting a malicious tar archive containing unvalidated hardlink or symlink entries. If the tar archive is extracted with elevated privileges, this flaw can lead to privilege escalation, enabling an attacker to gain unauthorized access to critical system files.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
