CVE WATCH / VULNERABILITY DETAIL

CVE-2026-56857

CRITICALCVSS 9.8NVD feed

Published 8 October 2026 · tracked since 9 October 2026

Description

On Windows, when the target of Root.Mkdir or Root.MkdirAll is a junction pointing to an empty location, the operation can create a directory at the junction target even when that target is located outside the root. This only applies to operations where the last path component is a junction (path/to/

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-56857 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-56857

CRITICALCVSS 9.8NVD feed

Published 8 October 2026 · tracked since 9 October 2026

Description

On Windows, when the target of Root.Mkdir or Root.MkdirAll is a junction pointing to an empty location, the operation can create a directory at the junction target even when that target is located outside the root. This only applies to operations where the last path component is a junction (path/to/

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]