CVE Intelligence
Skip to main content
HIGHpublic exploit

CVE-2026-24049

CVE-2026-24049 — wheel Allows Arbitrary File Permission Modification via Path Traversal

wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vulnerable to file permission modification through mishandling of file permissions after extraction. The logic blindly trusts the filename from the archive header for the chmod operation, even though the extraction process itself might have sanitized the path. Attackers can craft a malicious wheel file that, when unpacked, changes the permissions of critical system files (e.g., /etc/passwd, SSH keys, config files), allowing for Privilege Escalation or arbitrary code execution by modifying now-writable scripts. This issue has been fixed in version 0.46.2.

Published Updated Sources: cvelistV5, GitHub_M

Triage

Is it exploited, how likely is exploitation, what does it touch, and how severe do the scoring sources call it.

Exploitation

Exploit code

public exploit, none observed

EPSS

0%

chance of exploitation in 30 days

Affects

pypa

60 products listed

CVSS base

7.1

HIGH

CISA SSVC assessment

Three decision points CISA publishes for the CVEs it assesses · SSVC 2.0.3. A stakeholder decision, not a severity score.

CISA

Exploitation

PoC

none · proof-of-concept · active

Automatable

No

can an attacker script all four kill-chain steps

Technical impact

Partial

partial · total control of the vulnerable component

Affected scope

The catalog records vendors and products as separate lists, not pairs, so which product belongs to which vendor is not something this page can say.

Vendors (2)

Products (60)

wheeldiscovery 2 for rhel 10discovery 2 for rhel 8discovery 2 for rhel 9red hat ansible automation platform 2 5 for rhel 8red hat ansible automation platform 2 5 for rhel 9red hat ansible automation platform 2 6 for rhel 9red hat enterprise linux 10red hat enterprise linux 10 0 extended update supportred hat enterprise linux 8red hat enterprise linux 9red hat enterprise linux 9 4 extended update supportred hat enterprise linux 9 6 extended update supportnetwork observability netobserv 1 11 0red hat ai inference server 3 2red hat ansible automation platform 2 6red hat ceph storage 8 1red hat developer hub 1 8red hat discovery 2red hat openshift ai 2 25red hat openshift ai 3 3red hat openshift ai 3 4red hat openshift container platform 4 16red hat openshift container platform 4 17red hat openshift container platform 4 18red hat openshift container platform 4 19red hat openshift container platform 4 20red hat openshift container platform 4 21red hat openshift dev spaces 3 27red hat openstack 1 5red hat quay 3 10red hat quay 3 12red hat quay 3 13red hat quay 3 14red hat quay 3 15red hat quay 3 16red hat quay 3 9red hat satellite 6 18red hat trusted artifact signer 1 2red hat trusted artifact signer 1 3fence agents remediation operatorlogging subsystem for red hat openshiftmigration toolkit for virtualizationmulticluster engine for kubernetesopenshift lightspeedopenshift service mesh 2openshift service mesh 3red hat advanced cluster security 4red hat ai inference serverred hat ansible automation platform 2red hat ansible automation platform ansible core 2red hat enterprise linux 6red hat enterprise linux 7red hat enterprise linux ai rhel ai 3red hat openshift ai rhoaired hat openshift container platform 4red hat openshift dev spacesred hat quay 3red hat satellite 6service telemetry framework 1 5

Every base score collected

Sources score independently and disagree; each row says who scored it and under which version.

ScoreVersionSeverityExpl.ImpactSource
7.1CVSS 3.1HIGH——cvelistV5

Weakness & attack patterns

  • CWE-22
  • CWE-732

Attack patterns reported against this CVE. The ATT&CK techniques below are inferred from its weakness class.

  • T1574.010Hijack Execution Flow: ServicesFile Permissions Weakness
  • T1548Abuse Elevation Control Mechanism
  • T1083File and Directory Discovery

Public exploit

Capability, not use: code existing is a different claim from anyone running it.

Indexed by

poc in github

Detection

Read off the CVSS vector and the weakness class. Starting points, not rules we have tested.

  • Search application, proxy, and WAF logs for requests touching /etc/passwd.

References

25 on the record

Elsewhere on this site

  • pypaevery CVE for this vendor
  • redhatevery CVE for this vendor
  • CWE-22other pages naming this weakness

Not in any source we poll

Listed rather than left blank: an empty field and an unmeasured one look identical on screen, and only one is a reason to look elsewhere.

  • No confirmed IOCs, IP addresses, domains, file hashes, or malware artifacts supplied.
  • No organization-specific asset inventory, compensating-control status, or patch deployment evidence supplied.
  • No exploit packet captures, log samples, or incident case IDs supplied.