Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-40090

24
FAUCET Score

OVERVIEW CVE-2026-40090 is an arbitrary file write vulnerability affecting Zarf, an Airgap Native Packager Manager for Kubernetes, in versions 0.23.0 through 0.74.1. The vulnerability exists in the zarf package inspect sbom and zarf package inspect documentation subcommands, where attacker-controlled output directory paths can be exploited through crafted package metadata to write malicious files to arbitrary filesystem locations. SEVERITY The vulnerability carries a CVSS score of 7.1 (HIGH) with a network-based attack vector requiring minimal user interaction. An attacker can exploit this by modifying the Metadata.Name field in an unarchived package to include path traversal sequences (such as ../../etc/cron.d/malicious) or absolute paths targeting sensitive locations like SSH authorization keys. The attack allows writing arbitrary content to any filesystem location accessible by the user executing the inspect command, potentially enabling privilege escalation, unauthorized access, or system compromise. Attack complexity is low, though user interaction is required. EXPLOITATION STATUS This vulnerability is not currently listed on the Known Exploited Vulnerabilities catalog and shows no evidence of active exploitation in the wild. The EPSS score of 0.00046 indicates minimal probability of exploitation relative to the broader vulnerability landscape. The vulnerability has been patched in version 0.74.2, and organizations should prioritize upgrading to mitigate the risk.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0.23.0, < 0.74.2CPE matchmatch criteria
cpe:2.3:a:lfprojects:zarf:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.1HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
LOW
Exploitability Score
2.8
Impact Score
4.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.32%
Probability of exploitation in next 30 days
EPSS Percentile
24.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0032 is in the 29th percentile among its peer group of 14,855 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

gopatch availablevia ghsa
Product: github.com/zarf-dev/zarfFixed in: 0.74.2

Vendor Advisories (1)

goGHSA-pj97-4p9w-gx3qhigh

Zarf has a Path Traversal via Malicious Package Metadata.Name — Arbitrary File Write

Apr 14, 2026

References

github.com / zarf-dev/zarf/pull/4793
Issue TrackingPatch
github.com / zarf-dev/zarf/security/advisories/GHSA-pj97-4p9w-gx3q
PatchVendor Advisory