Description
A path traversal issue was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, watchOS 27. An app may be able to modify protected system files.
Published: 2026-09-14
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Modification of protected system files
Action: Update Devices
AI Analysis

Impact

Apple identified a path traversal issue that allowed applications to manipulate files that should have been guarded by the operating system. The flaw stems from insufficient validation of file path input, enabling an app to reference directories outside its intended scope. Unpatched to or overwrites critical system files, potentially leading to system instability or a break in security controls.

Affected Systems

The vulnerability affects Apple iOS and iPadOS versions prior to 26.7 and 27, as well as watchOS earlier than 27. The security update that mitigates the issue is included in iOS 26.7, iPadOS 26.7, iOS 27, iPadOS 27, and watchOS 27.

Risk and Exploitability

The EPSS score is less than 1%; the vulnerability is not listed in KEV and has a CVSS score of 5.5. An attacker would need to install or modify an app on the device to supply arbitrary file paths, and the path traversal flaw could allow the application to modify protected system files, potentially leading to system instability or security breaches.

Generated by OpenCVE AI on September 20, 2026 at 21:05 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the iOS 26.7 or later update, or iOS 27 if available.
  • Update iPadOS to 26.7 or later, or iPadOS 27 if available.
  • Apply the watchOS 27 update on all compatible Apple Watch devices.

Generated by OpenCVE AI on September 20, 2026 at 21:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Path Traversal Enables Modification of Protected System Files in iOS/iPadOS/watchOS

Fri, 18 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
Apple iphone Os
CPEs cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*
Vendors & Products Apple ipados
Apple iphone Os

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Title Path Traversal Allows Modification of Protected System Files and watchOS
Weaknesses CWE-20
CWE-22

Tue, 15 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Title Path Traversal Allows Modification of Protected System Files and watchOS
Weaknesses CWE-20
CWE-22

Tue, 15 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple watchos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A path traversal issue was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, watchOS 27. An app may be able to modify protected system files.
References

Subscriptions

Apple Ios And Ipados Ipados Iphone Os Watchos
cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-17T15:38:26.054Z

Reserved: 2026-09-08T16:43:41.872Z

Link: CVE-2026-86886

cve-icon Vulnrichment

Updated: 2026-09-17T15:38:15.997Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-14T21:17:39.553

Modified: 2026-09-18T15:01:44.480

Link: CVE-2026-86886

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T21:15:04Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')