# CVE-2026-44942

## Summary

- **CVE ID:** CVE-2026-44942
- **Severity:** MEDIUM
- **CVSS Score:** 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
- **CWE:** CWE-24
- **Published:** Jun 18, 2026
- **Last Modified:** Jun 20, 2026

## Description

A path traversal in handling the "path" component of .repo files processed by libzypp before 17.38.13 in the 17.x series, or before 16.22.19 could be used by attackers to fill directories on the system outside of the zypp cache with content.

## Affected Products

- SUSE — libzypp (17.0.0)
- SUSE — libzypp (0)

## References

- [CNA](https://bugzilla.suse.com/show_bug.cgi?id=1267874)
- [CNA](https://www.suse.com/security/cve/CVE-2026-44942.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.42%
- **EPSS Percentile:** 35.1

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._