PatchSiren cyber security CVE debrief
CVE-2026-87723 Google CVE debrief
CVE-2026-87723 is a vulnerability in Google fuse-archive versions prior to 1.24. An attacker can hijack the execution pathway by prepending a directory to PATH or writing a malicious binary to an attacker-controlled or writable directory appearing in PATH, allowing execution of arbitrary local code under the security context of the user running the fuse-archive process. The issue was partially mitigated in version 1.22 and fully resolved in 1.24 via refined selective PATH filtering.
- Vendor
- Product
- fuse-archive
- CVSS
- MEDIUM 5.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-28
- Original CVE updated
- 2026-09-28
- Advisory published
- 2026-09-28
- Advisory updated
- 2026-09-28
Who should care
Defenders and administrators responsible for systems using Google fuse-archive versions prior to 1.24 should assess exposure and prioritize updates to mitigate potential risks. This includes operators managing affected deployments, platform administrators, vulnerability management teams, and security teams that need to verify and update fuse-archive to version 1.24 or later, review and restrict PATH modifications and untrusted directories, and monitor for
Why it matters
CVE-2026-87723 in Google fuse-archive allows for arbitrary local code execution, requiring defenders to verify and update to version 1.24 or later, restrict PATH modifications, and monitor for suspicious activity.
- Execution of arbitrary local code under the security context of the user running fuse-archive
- Potential for lateral movement and privilege escalation
- Need for verifying and restricting PATH modifications and untrusted directories
- Prioritization of fuse-archive updates to version 1.24 or later
Technical summary
The vulnerability in Google fuse-archive versions prior to 1.24 allows an attacker to hijack the execution pathway by manipulating the PATH environment variable or writing a malicious binary to a directory in PATH. This can lead to execution of arbitrary local code under the security context of the user running fuse-archive. The issue was partially addressed in version 1.22 and fully resolved in version 1.24 through improved PATH filtering.
Defensive priority
Defenders should prioritize verifying and updating fuse-archive to version 1.24 or later, especially in environments where PATH modifications or untrusted directories are common.
Recommended defensive actions
- Verify and update fuse-archive to version 1.24 or later
- Review and restrict PATH modifications and untrusted directories
- Monitor for suspicious activity in environments with fuse-archive
- Perform vulnerability scanning to identify potential exposure
- Implement compensating controls for exposed systems
- Track exceptions and retest remediated assets
- whoShouldCare
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, its impact, and the fixes in versions 1.22 and 1.24 of fuse-archive. Defenders should verify and update fuse-archive to version 1.24 or later, review and restrict PATH modifications and untrusted directories, and monitor for suspicious activity in environments with fuse-archive. The vulnerability allows an attacker to hijack the execution pathway by manipulating the PATH environment variable or writing a malicious binary to a directory in PATH, leading to execution of
Sources and references
Verified primary and authoritative sources
-
CVE-2026-87723 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-87723
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-87723 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-87723
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/google/fuse-archive/commit/4b13a49b4bf66e0960241bab78987dde268a8b81
-
Source reference
Unverified legacy reference
URL: https://github.com/google/fuse-archive/commit/6f086e6381428d5b818dcb1bf7b9204e6bf017f0
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.