{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/izpack/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.4,"id":"CVE-2026-54550"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["izpack-installer"],"_cs_severities":["high"],"_cs_tags":["path-traversal","supply-chain","cve-2026-54550","izpack"],"_cs_type":"advisory","_cs_vendors":["IzPack"],"content_html":"\u003cp\u003eIzPack is a widely used open-source installer framework that creates Java-based installation packages. A critical path traversal vulnerability exists within the \u003ccode\u003eUnpackerBase.unpack()\u003c/code\u003e method (CVE-2026-54550), which resolves pack-file target paths without canonicalization or directory containment checks. Because IzPack installers lack digital signature requirements, an attacker can modify a legitimate installer JAR to include pack entries containing \u003ccode\u003e../\u003c/code\u003e traversal sequences. When a victim executes the modified installer, the application blindly writes malicious files to locations outside the intended installation directory, using the victim's privileges. This impact is exacerbated when installers are run with administrative privileges on Windows, enabling the placement of malicious binaries into system directories or startup folders to achieve persistent code execution. The vulnerability remains unpatched in the latest versions of the IzPack framework.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a software product that utilizes the IzPack framework for its distribution installer.\u003c/li\u003e\n\u003cli\u003eAttacker downloads the legitimate installer JAR and uses standard archival tools to extract its contents.\u003c/li\u003e\n\u003cli\u003eAttacker modifies the installer's pack configuration, adding entries with \u003ccode\u003e../\u003c/code\u003e traversal patterns in the \u003ccode\u003etargetPath\u003c/code\u003e attribute.\u003c/li\u003e\n\u003cli\u003eAttacker inserts a malicious payload (e.g., a backdoor executable) into the JAR package and references it with the traversed path.\u003c/li\u003e\n\u003cli\u003eAttacker distributes the trojanized installer through social engineering, deceptive websites, or supply chain compromise.\u003c/li\u003e\n\u003cli\u003eVictim executes the installer, often providing local administrator credentials as requested by the installation wizard.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eUnpackerBase.unpack()\u003c/code\u003e processes the malicious path, writing the payload into a sensitive location (e.g., startup folder).\u003c/li\u003e\n\u003cli\u003eSystem reboots or the victim performs an action that triggers the malicious binary, resulting in full system compromise.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for arbitrary file write and overwrite capabilities on the victim's system. Depending on the target path chosen by the attacker, this can lead to remote code execution, privilege escalation, and system persistence. Since IzPack installers are frequently run as privileged users during software installation, the impact is often a complete takeover of the host machine. Every user running software generated by IzPack versions 5.2.6 or earlier is potentially exposed to this supply-chain-style attack vector.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImplement file integrity monitoring (FIM) on sensitive system directories such as the Windows Startup folder and System32 to detect unexpected file writes following installer execution.\u003c/li\u003e\n\u003cli\u003eAdvise end-users to verify the authenticity and source of installer packages, prioritizing software obtained from verified vendor distribution channels over third-party repositories.\u003c/li\u003e\n\u003cli\u003eMonitor for the execution of Java-based installer processes that are spawned by unexpected parent processes or that exhibit unusual network connectivity after starting.\u003c/li\u003e\n\u003cli\u003eReview internally developed installers that leverage the IzPack framework for the presence of the vulnerable \u003ccode\u003eUnpackerBase\u003c/code\u003e component and mitigate by implementing manual path validation wrappers if code-level access is available.\u003c/li\u003e\n\u003cli\u003eProhibit the execution of unsigned or unverifiable installer packages in hardened production environments.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-26T23:13:30Z","date_published":"2026-08-26T23:13:30Z","id":"https://feed.craftedsignal.io/briefs/2026-08-izpack-path-traversal/","summary":"IzPack installer fails to validate target paths in UnpackerBase, allowing attackers to overwrite arbitrary files on the system by distributing trojanized, unsigned installer JARs.","title":"Path Traversal in IzPack UnpackerBase","url":"https://feed.craftedsignal.io/briefs/2026-08-izpack-path-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - IzPack","version":"https://jsonfeed.org/version/1.1"}