CVE-2026-41326

Source
https://cve.org/CVERecord?id=CVE-2026-41326
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-41326.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-41326
Aliases
Downstream
Related
Published
2026-04-24T18:46:21.993Z
Modified
2026-07-31T18:31:21.332464625Z
Severity
  • 8.2 (High) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:H/SI:N/SA:N CVSS Calculator
Summary
Kata Containers: CopyFile Policy Subversion via Symlinks
Details

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. From v3.4.0 to v3.28.0, an oversight in the CopyFile policy (and perhaps the CopyFile handler) allows untrusted hosts to write to arbitrary locations inside the guest workload image. This can be used to overwrite binaries inside the guest and exfiltrate data from containers; even those running inside CVMs. This vulnerability is fixed in v3.29.0.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-61"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41326.json"
}
References

Affected packages

Git / github.com/kata-containers/kata-containers

Affected ranges

Type
GIT
Repo
https://github.com/kata-containers/kata-containers
Events
Database specific
{
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ],
    "cpe": "cpe:2.3:a:katacontainers:kata_containers:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "3.4.0"
        },
        {
            "fixed": "3.29.0"
        }
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-41326.json"