Skip to main content
Echelon
Graph
Product
Enterprise
Compliance
Pulse
Exposures
AI Analyst
Compare
Docs
Login
Start Free
Pulse
›
Vendor Advisories
›
Microsoft Security Response Center (MSRC)
›
CVE-2026-18477
CVE-2026-18477
Medium
CVSS
4.4
Tar: tar: toctou in incremental dumpdir 'x' rename handling allows restore path escape
Vendor
Microsoft Security Response Center (MSRC)
Published
August 14, 2026
Last Modified
—
🔗 CVE IDs covered (1)
CVE-2026-18477 →
🎯 Affected products
1
azl3 tar 1.35-2 on Azure Linux 3.0
🔗 References (1)
advisory
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-18477