Description
A path traversal issue was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, watchOS 27. An app may be able to modify protected system files.
Published: 2026-09-14
Score: n/a
EPSS: n/a
KEV: No
Impact: Modification of protected system files
Action: Update Devices
AI Analysis

Impact

Apple identified a path traversal issue that allowed applications to manipulate files that should have been guarded by the operating system. The flaw stems from insufficient validation of file path input, enabling an app to reference directories outside its intended scope. Unpatched to or overwrites critical system files, potentially leading to system instability or a break in security controls.

Affected Systems

The vulnerability affects Apple iOS and iPadOS versions prior to 26.7 and 27, as well as watchOS earlier than 27. The security update that mitigates the issue is included in iOS 26.7, iPadOS 26.7, iOS 27, iPadOS 27, and watchOS 27.

Risk and Exploitability

No EPSS score or KEV listing is available, and a CVSS score is not published. The application that is able to supply arbitrary file paths, and would require the attacker to be able to install or modify an app on the device. Because the flaw can affect system files, compromise could result in a local privilege escalation or system integrity violation if successfully exploited.

Generated by OpenCVE AI on September 15, 2026 at 08:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the iOS 26.7 or later update, or iOS 27 if available;
  • Update iPadOS to 26.7 or later, or iPadOS 27 if available;
  • Apply the watchOS 27 update on all compatible Apple Watch devices.

Generated by OpenCVE AI on September 15, 2026 at 08:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple watchos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A path traversal issue was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, watchOS 27. An app may be able to modify protected system files.
References

Subscriptions

Apple Ios And Ipados Watchos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-14T20:48:40.053Z

Reserved: 2026-09-08T16:43:41.872Z

Link: CVE-2026-86886

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-14T21:17:39.553

Modified: 2026-09-14T21:17:39.553

Link: CVE-2026-86886

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T03:15:09Z

Weaknesses

No weakness.