PatchSiren

izpack CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH izpack CVE published 2026-08-26

CVE-2026-54550

IzPack vulnerability allows for arbitrary file write outside intended installation directory. The vulnerability exists in version 5.2.6 and earlier of the UnpackerBase.unpack() method, which does not properly normalize file paths, allowing an attacker to write files outside the intended installation directory. This could lead to potential privilege escalation and system compromise. Developers and administ [truncated]