CVE-2026-56857: Root.Mkdir(All) can follow junctions out of the root on Windows in os

Published Oct 8, 2026
·
Updated

On Windows, when the target of Root.Mkdir or Root.MkdirAll is a junction pointing to an empty location, the operation can create a directory at the junction target even when that target is located outside the root. This only applies to operations where the last path component is a junction (path/to/junction, but not path/junction/target).

Affected Software

1 affected component
Google Go

Event History

Oct 8, 2026
CVE Published
via MITRE·10:53 PM
Data Sourced
via MITRE·10:53 PM
DescriptionWeakness
Data Sourced
via NVD·11:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

How can I determine whether my code is exposed to this behavior?

Review Windows code paths that call Root.Mkdir or Root.MkdirAll where the final path component may be a junction. Exposure requires that the junction point to an empty location outside the intended root.

2

Are directory creations below a junction also affected?

No. The issue applies when the junction is the last path component, such as path/to/junction, and not when creating a descendant such as path/junction/target.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203