VYPR
High severity7.8NVD Advisory· Published Apr 1, 2022· Updated Jun 17, 2026

CVE-2021-26623

CVE-2021-26623

Description

A remote code execution vulnerability due to incomplete check for 'xheader_decode_path_record' function's parameter length value in the ark library. Remote attackers can induce exploit malicious code using this function.

Affected products

3
  • cpe:2.3:a:bandisoft:bandizip:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:bandisoft:bandizip:*:*:*:*:*:*:*:*range: <7.19
    • (no CPE)range: unspecified
  • Ark/arkllm-create

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.