CVE-2026-5704 is a file injection vulnerability in tar that allows attackers to bypass pre-extraction inspection mechanisms by crafting malicious archives containing hidden files with attacker-controlled content. This flaw potentially enables unauthorized introduction of malicious files onto systems without detection during the extraction process. The vulnerability is rated CVSS 5.5 MEDIUM severity with a local attack vector requiring user interaction but no special privileges. While the confidentiality impact is none, the integrity impact is rated high, meaning successful exploitation could compromise system integrity through the injection of unauthorized files. There is no current evidence of active exploitation. The vulnerability does not appear on the Known Exploited Vulnerabilities (KEV) catalog and remains inactive on threat tracking lists. The extremely low EPSS score of 0.000320000 indicates minimal real-world exploitation activity compared to other disclosed vulnerabilities, suggesting this remains a low-priority concern despite its integrity impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:gnu:tar:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:redhat:hardened_images:-:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.