wheel 0.40.00.46.1: Permission Bypass via malicious wheel, PrivEsc
CVE-2026-24049 Published on January 22, 2026
wheel Allows Arbitrary File Permission Modification via Path Traversal
wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vulnerable to file permission modification through mishandling of file permissions after extraction. The logic blindly trusts the filename from the archive header for the chmod operation, even though the extraction process itself might have sanitized the path. Attackers can craft a malicious wheel file that, when unpacked, changes the permissions of critical system files (e.g., /etc/passwd, SSH keys, config files), allowing for Privilege Escalation or arbitrary code execution by modifying now-writable scripts. This issue has been fixed in version 0.46.2.
Vulnerability Analysis
CVE-2026-24049 can be exploited with local system access, requires user interaction. This vulnerability is considered to have a low attack complexity. Public availability of a proof of concept (POC) exploit exists for CVE-2026-24049. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality, a high impact on integrity and availability.
Privileges Required:
NONE
User Interaction:
REQUIRED
Confidentiality Impact:
NONE
Availability Impact:
HIGH
Weakness Types
What is a Directory traversal Vulnerability?
The software uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the software does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CVE-2026-24049 has been classified to as a Directory traversal vulnerability or weakness.
Incorrect Permission Assignment for Critical Resource
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. When a resource is given a permissions setting that provides access to a wider range of actors than required, it could lead to the exposure of sensitive information, or the modification of that resource by unintended parties. This is especially dangerous when the resource is related to program configuration, execution or sensitive user data.
Products Associated with CVE-2026-24049
Want to know whenever a new CVE is published for Red Hat products? stack.watch will email you.
Affected Versions
pypa
wheel:
-
Version >= 0.40.0, < 0.46.2
is affected.
Red Hat
Discovery 2 for RHEL 10:
-
Version 0:2.4.3-2.el10 and below *
is unaffected.
Red Hat
Discovery 2 for RHEL 8:
-
Version 0:2.4.3-2.el8 and below *
is unaffected.
Red Hat
Discovery 2 for RHEL 9:
-
Version 0:2.4.3-2.el9 and below *
is unaffected.
Red Hat Ansible Automation Platform 2.5 for RHEL 8:
-
Version 0:4.6.26-1.el8ap and below *
is unaffected.
Red Hat Ansible Automation Platform 2.5 for RHEL 9:
-
Version 0:4.6.26-1.el9ap and below *
is unaffected.
Red Hat Ansible Automation Platform 2.6 for RHEL 9:
-
Version 0:4.7.9-1.el9ap and below *
is unaffected.
Red Hat Enterprise Linux 10:
-
Version 1:0.41.2-5.el10_1.1 and below *
is unaffected.
Red Hat Enterprise Linux 10.0 Extended Update Support:
-
Version 1:0.41.2-5.el10_0.1 and below *
is unaffected.
Red Hat Enterprise Linux 8:
-
Version 0:0.41.2-4.el8_10 and below *
is unaffected.
Red Hat Enterprise Linux 9:
-
Version 0:0.41.2-3.el9_7.1 and below *
is unaffected.
Red Hat Enterprise Linux 9.4 Extended Update Support:
-
Version 0:0.41.2-3.el9_4.1 and below *
is unaffected.
Red Hat Enterprise Linux 9.6 Extended Update Support:
-
Version 0:0.41.2-3.el9_6.1 and below *
is unaffected.
Red Hat
Network Observability (NETOBSERV) 1.11.2:
-
Version 1771231259 and below *
is unaffected.
Red Hat AI Inference Server 3.2:
-
Version 1772160593 and below *
is unaffected.
Red Hat AI Inference Server 3.2:
-
Version 1772160625 and below *
is unaffected.
Red Hat Ansible Automation Platform 2.6:
-
Version 1777176989 and below *
is unaffected.
Red Hat Ansible Automation Platform 2.6:
-
Version 1772486590 and below *
is unaffected.
Red Hat Ansible Automation Platform 2.6:
-
Version 1772525069 and below *
is unaffected.
Red Hat Developer Hub 1.8:
-
Version 1770656494 and below *
is unaffected.
Red Hat Discovery 2:
-
Version 1770913597 and below *
is unaffected.
Red Hat OpenShift AI 2.25:
-
Version 1776338381 and below *
is unaffected.
Red Hat OpenShift AI 2.25:
-
Version 1770103375 and below *
is unaffected.
-
Version 1770786633 and below *
is unaffected.
Red Hat OpenShift AI 2.25:
-
Version 1772094445 and below *
is unaffected.
Red Hat OpenShift AI 2.25:
-
Version 1772093252 and below *
is unaffected.
Red Hat OpenShift AI 2.25:
-
Version 1772093260 and below *
is unaffected.
Red Hat OpenShift AI 2.25:
-
Version 1772093338 and below *
is unaffected.
Red Hat OpenShift AI 2.25:
-
Version 1772093324 and below *
is unaffected.
Red Hat OpenShift AI 3.3:
-
Version 1778262952 and below *
is unaffected.
Red Hat OpenShift AI 3.3:
-
Version 1778263271 and below *
is unaffected.
Red Hat OpenShift AI 3.3:
-
Version 1770956034 and below *
is unaffected.
Red Hat OpenShift AI 3.4:
-
Version 1772204882 and below *
is unaffected.
Red Hat OpenShift Container Platform 4.16:
-
Version 1779252096 and below *
is unaffected.
Red Hat OpenShift Container Platform 4.17:
-
Version 1778709698 and below *
is unaffected.
Red Hat OpenShift Container Platform 4.18:
-
Version 1774856889 and below *
is unaffected.
Red Hat OpenShift Container Platform 4.19:
-
Version 1775604154 and below *
is unaffected.
Red Hat OpenShift Container Platform 4.20:
-
Version 1774851817 and below *
is unaffected.
Red Hat OpenShift Container Platform 4.21:
-
Version 1774891432 and below *
is unaffected.
Red Hat OpenShift Dev Spaces 3.27:
-
Version 1774609756 and below *
is unaffected.
Red Hat OpenShift Dev Spaces 3.27:
-
Version 1774070844 and below *
is unaffected.
Red Hat OpenShift Dev Spaces 3.27:
-
Version 1774451954 and below *
is unaffected.
Red Hat OpenStack 1.5:
-
Version 1777452540 and below *
is unaffected.
Red Hat Quay 3.10:
-
Version 1770249183 and below *
is unaffected.
Red Hat Quay 3.12:
-
Version 1773771962 and below *
is unaffected.
Red Hat Quay 3.13:
-
Version 1773088862 and below *
is unaffected.
Red Hat Quay 3.14:
-
Version 1773097621 and below *
is unaffected.
Red Hat Quay 3.15:
-
Version 1770146565 and below *
is unaffected.
Red Hat Quay 3.16:
-
Version 1770836901 and below *
is unaffected.
Red Hat Quay 3.9:
-
Version 1770856103 and below *
is unaffected.
Red Hat Satellite 6.18:
-
Version 1769520238 and below *
is unaffected.
Red Hat Trusted Artifact Signer 1.2:
-
Version 1770739020 and below *
is unaffected.
Red Hat Trusted Artifact Signer 1.3:
-
Version 1770108732 and below *
is unaffected.
Red Hat Trusted Artifact Signer 1.3:
-
Version 1772614635 and below *
is unaffected.
Red Hat
Fence Agents Remediation Operator:
Logging Subsystem for Red Hat OpenShift:
Logging Subsystem for Red Hat OpenShift:
Logging Subsystem for Red Hat OpenShift:
Logging Subsystem for Red Hat OpenShift:
Logging Subsystem for Red Hat OpenShift:
Logging Subsystem for Red Hat OpenShift:
Red Hat
Migration Toolkit for Virtualization:
Red Hat
Migration Toolkit for Virtualization:
Red Hat
Multicluster Engine for Kubernetes:
Red Hat
Multicluster Engine for Kubernetes:
Red Hat
OpenShift Lightspeed:
Red Hat
OpenShift Lightspeed:
Red Hat
OpenShift Lightspeed:
Red Hat
OpenShift Lightspeed:
Red Hat
OpenShift Service Mesh 2:
Red Hat
OpenShift Service Mesh 2:
Red Hat
OpenShift Service Mesh 2:
Red Hat
OpenShift Service Mesh 2:
Red Hat
OpenShift Service Mesh 2:
Red Hat
OpenShift Service Mesh 2:
Red Hat
OpenShift Service Mesh 2:
Red Hat
OpenShift Service Mesh 2:
Red Hat
OpenShift Service Mesh 3:
Red Hat Advanced Cluster Security 4:
Red Hat AI Inference Server:
Red Hat AI Inference Server:
Red Hat AI Inference Server:
Red Hat AI Inference Server:
Red Hat Ansible Automation Platform 2:
Red Hat Ansible Automation Platform 2:
Red Hat Ansible Automation Platform 2:
Red Hat Ansible Automation Platform 2:
Red Hat Ansible Automation Platform 2:
Red Hat Ansible Automation Platform 2:
Red Hat Ansible Automation Platform 2:
Red Hat Ansible Automation Platform 2:
Red Hat Ansible Automation Platform 2:
Red Hat Ansible Automation Platform 2:
Red Hat Ansible Automation Platform 2:
Red Hat Ansible Automation Platform 2:
Red Hat Ansible Automation Platform 2:
Red Hat Ansible Automation Platform 2:
Red Hat Ansible Automation Platform 2:
Red Hat Ansible Automation Platform 2:
Red Hat Ansible Automation Platform 2:
Red Hat Ansible Automation Platform 2:
Red Hat Ansible Automation Platform 2:
Red Hat Ansible Automation Platform 2:
Red Hat Ansible Automation Platform 2:
Red Hat Ansible Automation Platform 2:
Red Hat Ansible Automation Platform 2:
Red Hat Ansible Automation Platform 2:
Red Hat Ansible Automation Platform 2:
Red Hat Ansible Automation Platform 2:
Red Hat Ansible Automation Platform 2:
Red Hat Ansible Automation Platform 2:
Red Hat Ansible Automation Platform 2:
Red Hat Ansible Automation Platform 2:
Red Hat Ansible Automation Platform Ansible Core 2:
Red Hat Ansible Automation Platform Ansible Core 2:
Red Hat Ansible Automation Platform Ansible Core 2:
Red Hat Ansible Automation Platform Ansible Core 2:
Red Hat Enterprise Linux 10:
Red Hat Enterprise Linux 6:
Red Hat Enterprise Linux 7:
Red Hat Enterprise Linux 8:
Red Hat Enterprise Linux 8:
Red Hat Enterprise Linux 9:
Red Hat Enterprise Linux 9:
Red Hat Enterprise Linux 9:
Red Hat Enterprise Linux AI (RHEL AI) 3:
Red Hat Enterprise Linux AI (RHEL AI) 3:
Red Hat Enterprise Linux AI (RHEL AI) 3:
Red Hat Enterprise Linux AI (RHEL AI) 3:
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift AI (RHOAI):
Red Hat OpenShift Container Platform 4:
Red Hat OpenShift Container Platform 4:
Red Hat OpenShift Container Platform 4:
Red Hat OpenShift Container Platform 4:
Red Hat OpenShift Container Platform 4:
Red Hat OpenShift Container Platform 4:
Red Hat OpenShift Container Platform 4:
Red Hat OpenShift Dev Spaces:
Red Hat Quay 3:
Red Hat Quay 3:
Red Hat Quay 3:
Red Hat Quay 3:
Red Hat Quay 3:
Red Hat Quay 3:
Red Hat Quay 3:
Red Hat Satellite 6:
Red Hat Satellite 6:
Red Hat Satellite 6:
Red Hat Satellite 6:
Red Hat Satellite 6:
Red Hat Satellite 6:
Red Hat Satellite 6:
Red Hat Satellite 6:
Red Hat
Service Telemetry Framework 1.5:
Red Hat
Service Telemetry Framework 1.5:
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.