VU#293714: Arbitrary File Overwrite in Develar app-builder (zipx.Unzip) via Symlink Following on macOS (APFS)

2026-07-29T20:52:05Z9e20cc6207218a5d447167b5cd288a6eec050b2c508333a6c915486d2b39e7b8
CVE-2026-14985CVE-2026-15342CVE-2026-15611CVE-2026-15612CVE-2026-16157CVE-2026-16637CVE-2026-16771APFSArris BGW210-700CERT/CCDLL-hijackingElectronLogtoMFA-bypassOIDCOPeNDAPSAMLSSOSSRFUnicode-normalizationWindowsaccount-takeoverarbitrary-code-executionarbitrary-file-overwriteauthentication-bypassauthorization-bypasscredential-disclosurelocal-privilege-escalationmacOSmulti-tenant-isolationpath-traversalsymlink-following

What happened

CERT/CC advisories describe multiple vulnerabilities across developer tooling, data services, identity platforms, network gateways, backup software, media servers, and project-management software. Issues include arbitrary file overwrite, SSRF and credential disclosure, authentication bypass, SSO/account takeover and MFA bypass, local privilege escalation, elevated code execution, and multi-tenant authorization bypass. Several have published CVEs, while the app-builder and Plane issues lack a CVE in the supplied records.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
certcc_vulnotes
Record identifier
9e20cc6207218a5d447167b5cd288a6eec050b2c508333a6c915486d2b39e7b8
Enrichment time
2026-07-29T20:52:05Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.