Description
BandiZip v.7.37 is affected by a Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of BandiZip
Published: 2026-07-22
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in BandiZip 7.37 allows attackers to bypass the Mark‑of‑the‑Web protection mechanism that normally flags files downloaded from the internet, preventing accidental execution. Based on the description, the flaw is a failure to enforce correct authentication or control mechanisms, classified as CWE‑693. Bypassing this protection can lead to unintended code execution under the user’s privileges when malicious archives are opened.

Affected Systems

Only the 7.37 release of BandiZip is explicitly listed as affected. The advisory does not mention other versions or related products. Based on the available data, systems running this specific version may be at risk, whereas earlier or later releases are not confirmed to contain the flaw.

Risk and Exploitability

The likely attack vector, inferred from the description, is a remote attacker delivering a crafted archive that, when opened with BandiZip, bypasses the Mark‑of‑the‑Web check. The CVSS score of 5.4 indicates moderate severity, while the EPSS score of <1% suggests low likelihood of exploitation at present. The vulnerability is not in the CISA KEV catalog, so there is no known widespread exploitation. The bypass does not require local privileged access and can be triggered by any user who can place files in the extraction path, making the risk spread to all users of that installation.

Generated by OpenCVE AI on August 4, 2026 at 15:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest BandiZip update that corrects the Mark‑of‑the‑Web bypass if one is released.
  • Disable the Mark‑of‑the‑Web enforcement setting within BandiZip to prevent unsigned archives from being treated as trusted.
  • Use application whitelisting or disable autorun for files extracted by BandiZip to block unintended execution of malicious content.
  • Continuously monitor extraction logs for unusual activity to detect possible exploitation attempts.

Generated by OpenCVE AI on August 4, 2026 at 15:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Title Bypass of Mark‑of‑the‑Web Protection in BandiZip 7.37

Sun, 02 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Title Authentication Bypass Allowing Mark‑of‑the‑Web Protection Bypass in BandiZip 7.37

Mon, 27 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Authentication Bypass Allowing Mark‑of‑the‑Web Protection Bypass in BandiZip 7.37

Fri, 24 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 07:00:00 +0000

Type Values Removed Values Added
First Time appeared Bandisoft
Bandisoft bandizip
Vendors & Products Bandisoft
Bandisoft bandizip

Wed, 22 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description BandiZip v.7.37 is affected by a Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of BandiZip
References

Subscriptions

Bandisoft Bandizip
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-24T19:17:11.474Z

Reserved: 2025-06-16T00:00:00.000Z

Link: CVE-2025-50325

cve-icon Vulnrichment

Updated: 2026-07-24T19:16:46.011Z

cve-icon NVD

Status : Deferred

Published: 2026-07-22T21:17:11.647

Modified: 2026-07-24T20:17:01.467

Link: CVE-2025-50325

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T16:00:12Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure