Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 521
Alerts This Week
Warning Icon 1 521

SUSE Apache-Ivy Moderate Directory Traversal Threat Update 2026-22858-1

suse
Calendar Grey July 27, 2026
Scroller Suse
An update for apache-ivy addresses a moderate risk directory traversal issue allowing file overwriting. Install immediately.
A security update for apache-ivy addresses CVE-2026-26032, which could allow file overwriting outside the configured directory, and introduces various improvements and features for...

Summary

## This update for apache-ivy fixes the following issue: * CVE-2026-26032: directory traversal sequences in module coordinates can allow overwriting arbitrary files outside the configured "buildRoot" directory (bsc#1271727). Changes for apache-ivy: * Upgrade to 2.6.0: * the ivy:retrieve task failed when the retrieve pattern contained some text in parentheses before the first token, for instance: /jobs/lib (JDK 17)/[artifact].[ext] (IVY-1660) * when the ivy:deliver task is configured to replace dynamic revisions, it now replaces these revisions to the resolved revision before any conflict resolution was done, which was the original behavior before Ivy 2.3.0. This way, the delivered ivy.xml can be used to have reproducible dependency

References

* bsc#1271727

Cross-

* CVE-2026-26032

CVSS scores:

* CVE-2026-26032 ( SUSE ): 5.9

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

* CVE-2026-26032 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N

* CVE-2026-26032 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Affected Products:

* SUSE Linux Enterprise Server 16.0

* SUSE Linux Enterprise Server for SAP applications 16.0

An update that solves one vulnerability can now be installed.

##

* https://www.suse.com/security/cve/CVE-2026-26032.html

* https://bugzilla.suse.com/show_bug.cgi?id=1271727

Severity
moderate
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:22858-1
Release Date: 2026-07-22T17:49:04Z
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.