Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 28 Jun 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | 7-Zip for Windows through 26.02 fails to preserve the Mark-of-the-Web when extracting a crafted RAR5 archive, because its guard that suppresses an archive-supplied Zone.Identifier stream matches the exact name 'Zone.Identifier' while a RAR5 STM record named ':Zone.Identifier:$DATA' is not matched and NTFS canonicalizes it to the same stream, overwriting the propagated Internet-zone marker with ZoneId=0. A second STM record named '::$DATA' overwrites the extracted file's default data stream, letting an attacker defeat SmartScreen/MotW warnings and spoof file content. | |
| Title | 7-Zip - Mark-of-the-Web Bypass via RAR5 Alternate Data Stream Name Collision | |
| First Time appeared |
7-zip
7-zip 7-zip |
|
| Weaknesses | CWE-693 | |
| CPEs | cpe:2.3:a:7-zip:7-zip:*:*:*:*:*:*:*:* | |
| Vendors & Products |
7-zip
7-zip 7-zip |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-28T01:32:54.971Z
Reserved: 2026-06-28T00:55:25.426Z
Link: CVE-2026-58052
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-28T06:45:04Z