CVE-2026-41326
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like cont
CVSS
8.2
Alto
EPSS
0.3%
p28
KEV
—
Exploit Today
8
0-100
Publicado: 24 abr 2026 · Última mod.: 24 ago 2026 · CWE-61 · CWE-1220
0.3%EPSS · 30 días0.3%
2026-08-182026-09-15
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. From v3.4.0 to v3.28.0, an oversight in the CopyFile policy (and perhaps the CopyFile handler) allows untrusted hosts to write to arbitrary locations inside the guest workload image. This can be used to overwrite binaries inside the guest and exfiltrate data from containers; even those running inside CVMs. This vulnerability is fixed in v3.29.0.
- github.comhttps://github.com/kata-containers/kata-containers/commit/1b9e49eb2763aa6ea6a99b276d3ff5e2c7f658f2
- github.comhttps://github.com/kata-containers/kata-containers/security/advisories/GHSA-q49m-57vm-c8cc
- www.openwall.comhttp://www.openwall.com/lists/oss-security/2026/05/13/2
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:25200
- access.redhat.comhttps://access.redhat.com/security/cve/CVE-2026-41326
- bugzilla.redhat.comhttps://bugzilla.redhat.com/show_bug.cgi?id=2460859
- github.comhttps://github.com/kata-containers/kata-containers/security/advisories/GHSA-q49m-57vm-c8cc
- security.access.redhat.comhttps://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41326.json
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-906167.4 ALT6.3%
——2In Flatpak before 1.18.1, a malicious sandboxed app can obtain arbitrary read and write access to files on the host, which can be escalated to arbitrary code execution on the host, a different vulnerability than CVE-2026-76925. Flatpak creates a few app data directories (e.g., /var/cache, /var/data, /var/config, and /var/tmp) in every sandbox on every app launch where, in some cases, components of the path are attacker-controlled. Missing symlink protection can redirect the directories. Some of these directories are bind-mounted by Flatpak by passing the path (e.g., /home/user/.var/app/APP_ID/cache/tmp), which contains attacker-controlled directories (tmp) to bwrap --bind SRC DST. bwrap passes the path on to the kernel, which then follows symlinks. A malicious symlink can point to arbitrary locations on the host and it will become mounted inside the sandbox.2dCVE-2026-771595.5 MED5.8%
——2A symlink-following flaw was found in libvirt's qemuTPMEmulatorPrepareHost() function. The function uses a path-based chown() on the swtpm logfile without checking for symbolic links. A local attacker with access to the swtpm account can replace the logfile with a symlink, causing libvirtd (running as root) to transfer ownership of an arbitrary file to the swtpm user.1dCVE-2026-578255.7 MED24.1%
——7In the opam package before 2.5.2 for OCaml, the sandbox protection mechanism can be bypassed because symlinks are mishandled during use of .install files.2dCVE-2026-774808.8 ALT43.8%
——13Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.1dCVE-2026-692676.5 MED18.4%
——6Insufficient granularity of access control in Windows Connected User Experiences and Telemetry allows an authorized attacker to disclose information locally.8dCVE-2026-668148.8 ALT36.1%
——11Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.7h