CVE-2024-11218
A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 and a race condition
CVSS
8.6
Alto
EPSS
0.4%
p30
KEV
—
Exploit Today
9
0-100
Publicado: 22 ene 2025 · Última mod.: 31 ago 2026 · CWE-269
0.4%EPSS · 30 días0.4%
2026-08-202026-09-17
A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 and a race condition when building a malicious Containerfile. SELinux might mitigate it, but even with SELinux on, it still allows the enumeration of files and directories on the host.
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2025:0830
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2025:0878
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2025:0922
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2025:0923
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2025:1186
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2025:1187
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2025:1188
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2025:1189
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2025:1207
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2025:1275
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2025:1295
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2025:1296
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2025:1372
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2025:1453
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2025:1707
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2025:1713
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2025:1908
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2025:1910
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2025:1914
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2025:2441
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-202876.5 MED11.8%
——4As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) engineering teams have conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.
The vulnerabilities tracked by CVE-2026-20287 are related to improper privilege managment issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-269.1dCVE-2026-269476.7 MED5.9%
——2Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.4.0.0, contains an Improper Privilege Management vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.2dCVE-2026-88817—19.7%
——6An authenticated, non-guest user of Curiosity Workspace could enroll themselves as an administrator and member of an existing access group without an invitation or approval.
It did not grant application-wide administrator privileges, and the vulnerability could not be used to obtain root access to the application or its underlying host.2dCVE-2026-127939.8 CRÍ32.6%
——10The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.6.2. This is due to the plugin not validating that a submitted form ID belongs to a JetFormBuilder form before parsing the referenced post's content as form schema and executing an Advanced Validation server-side callback. This makes it possible for unauthenticated attackers to create a new administrator-level user account.2dCVE-2026-766946.6 MED35.8%
——11A privilege escalation vulnerability exists in the command line interface of HPE Networking EdgeConnect SD-WAN Gateways. Successful exploitation could allow an authenticated remote attacker with high privileges to escalate privileges beyond their authorized level, and execute arbitrary code on a vulnerable system.2dCVE-2026-794118.8 ALT24.0%
——7Incorrect privilege assignment in the admin user-management component of Webkul Bagisto 2.4.9 allows an authenticated backend user holding only the settings.users.edit permission to escalate to full administrator. The user-update endpoint (route admin.settings.users.update, UserController::update()) does not verify that the actor is permitted to grant the requested role, does not prevent a user from changing their own role, and does not restrict assignment to roles whose permission set is a subset of the actor's own. By submitting a request that sets role_id to the Administrator role for their own account, a low-privileged administrator gains every admin-panel capability, including store configuration, payment gateway credentials, and customer PII.2d