CVE-2026-56857 - Root.Mkdir(All) can follow junctions out of the root on Windows in os
CVE ID :CVE-2026-56857
Published : Oct. 8, 2026, 11:17 p.m. | 2 hours, 29 minutes ago
Description :On Windows, when the target of Root.Mkdir or Root.MkdirAll is a junction pointing to an empty location, the operation can create a directory at the junction target even when that target is located outside the root. This only applies to operations where the last path component is a junction (path/to/junction, but not path/junction/target).
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Oct. 8, 2026, 11:17 p.m. | 2 hours, 29 minutes ago
Description :On Windows, when the target of Root.Mkdir or Root.MkdirAll is a junction pointing to an empty location, the operation can create a directory at the junction target even when that target is located outside the root. This only applies to operations where the last path component is a junction (path/to/junction, but not path/junction/target).
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...