CVE-2026-32637

medium VMware
EPSS Score
0.5%
Exploitation probability in 30 days
Top 58% most likely to be exploited
Published: August 25, 2026 (11 days ago)
Last Modified: August 28, 2026
Vendor: VMware
Source: NVD

Description

Velero is an open source tool for backing up, restoring, and migrating Kubernetes cluster resources and persistent volumes. Prior to 1.18.1, an attacker who compromises the backup object-storage backend can upload a malicious backup tarball containing parent-directory paths that escape the extraction directory during restore and overwrite sensitive files in the Velero pod filesystem. This issue is fixed in version 1.18.1.

CWE

CWE-22

References