Skip to main content
Echelon
Graph
Product
Enterprise
Compliance
Pulse
More Pulse pages
Exposures
AI Analyst
Compare
Radar
Book a Demo
Pulse
›
Vendor Advisories
›
Microsoft Security Response Center (MSRC)
›
CVE-2026-18477
CVE-2026-18477
Medium
CVSS
4.4
Tar: tar: toctou in incremental dumpdir 'x' rename handling allows restore path escape
Vendor
Microsoft Security Response Center (MSRC)
Published
August 14, 2026
Last Modified
—
🔗 CVE IDs covered (1)
CVE-2026-18477 →
🎯 Affected products
1
azl3 tar 1.35-2 on Azure Linux 3.0
✅ Remediation
Security Update
🔗 References (2)
advisory
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-18477
patch
https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade