CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-32637

mediumcovered by 2 sourcesfirst seen 2026-08-20
Impact _What kind of vulnerability is it? Who is impacted?_ If the attacker compromises the backup's object storage backend and uploads a malicious backup tarball including file names like the following: - ../../../tmp/escape_1 -> file created at /tmp/escape_1 - ../../../../../../../../tmp/escape_2 -> file created at /tmp/escape_2 - ../../../tmp/cron_poc -> would be /etc/cron.d/backdoor in real attack - ../../../tmp/ssh_poc -> would be ~/.ssh/authorized_keys - ../../../tmp/kubeconfig_poc -> would be ~/.kube/config It's possible that extracting files from the tarball during restore can overwrite sensitive files in the Velero pod filesystem. Patches _Has the problem been patched? What versions should users upgrade to?_ By far, there is no patch yet. We are working on the main branch, then cherry-pick to the release-1.18 for v1.18.1 patch. Workarounds _Is there a way for users to fix or remediate the vulnerability without upgrading?_ There is no workaround, but the good news is that keeping your OSS safe will prevent the vulnerability.

⚡ Watch CVE-2026-32637

Get an email if CVE-2026-32637 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (2)

External references

NVD record for CVE-2026-32637

CVE.org record

Embed the live status

CVE-2026-32637 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-32637 status](https://www.csirts.com/badge/CVE-2026-32637)](https://www.csirts.com/cve/CVE-2026-32637)