PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-87723 Google CVE debrief

CVE-2026-87723 is a vulnerability in Google fuse-archive versions prior to 1.24. An attacker can hijack the execution pathway by prepending a directory to PATH or writing a malicious binary to an attacker-controlled or writable directory appearing in PATH, allowing execution of arbitrary local code under the security context of the user running the fuse-archive process. The issue was partially mitigated in version 1.22 and fully resolved in 1.24 via refined selective PATH filtering.

Vendor
Google
Product
fuse-archive
CVSS
MEDIUM 5.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-28
Original CVE updated
2026-09-28
Advisory published
2026-09-28
Advisory updated
2026-09-28

Who should care

Defenders and administrators responsible for systems using Google fuse-archive versions prior to 1.24 should assess exposure and prioritize updates to mitigate potential risks. This includes operators managing affected deployments, platform administrators, vulnerability management teams, and security teams that need to verify and update fuse-archive to version 1.24 or later, review and restrict PATH modifications and untrusted directories, and monitor for

Why it matters

CVE-2026-87723 in Google fuse-archive allows for arbitrary local code execution, requiring defenders to verify and update to version 1.24 or later, restrict PATH modifications, and monitor for suspicious activity.

  • Execution of arbitrary local code under the security context of the user running fuse-archive
  • Potential for lateral movement and privilege escalation
  • Need for verifying and restricting PATH modifications and untrusted directories
  • Prioritization of fuse-archive updates to version 1.24 or later

Technical summary

The vulnerability in Google fuse-archive versions prior to 1.24 allows an attacker to hijack the execution pathway by manipulating the PATH environment variable or writing a malicious binary to a directory in PATH. This can lead to execution of arbitrary local code under the security context of the user running fuse-archive. The issue was partially addressed in version 1.22 and fully resolved in version 1.24 through improved PATH filtering.

Defensive priority

Defenders should prioritize verifying and updating fuse-archive to version 1.24 or later, especially in environments where PATH modifications or untrusted directories are common.

Recommended defensive actions

  • Verify and update fuse-archive to version 1.24 or later
  • Review and restrict PATH modifications and untrusted directories
  • Monitor for suspicious activity in environments with fuse-archive
  • Perform vulnerability scanning to identify potential exposure
  • Implement compensating controls for exposed systems
  • Track exceptions and retest remediated assets
  • whoShouldCare

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, its impact, and the fixes in versions 1.22 and 1.24 of fuse-archive. Defenders should verify and update fuse-archive to version 1.24 or later, review and restrict PATH modifications and untrusted directories, and monitor for suspicious activity in environments with fuse-archive. The vulnerability allows an attacker to hijack the execution pathway by manipulating the PATH environment variable or writing a malicious binary to a directory in PATH, leading to execution of

Sources and references

Verified primary and authoritative sources

  • CVE-2026-87723 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-87723

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-87723 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-87723

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.