CVE-2026-41326 Details
Description
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. From v3.4.0 to v3.28.0, an oversight in the CopyFile policy (and perhaps the CopyFile handler) allows untrusted hosts to write to arbitrary locations inside the guest workload image. This can be used to overwrite binaries inside the guest and exfiltrate data from containers; even those running inside CVMs. This vulnerability is fixed in v3.29.0.
A vulnerability in Kata Containers versions 3.4.0 to 3.28.0 allows untrusted hosts to write to arbitrary locations within guest workload images. This oversight in the CopyFile policy and possibly the CopyFile handler can be exploited to overwrite binaries inside the guest and exfiltrate data from containers, including those running in Confidential Virtual Machines (CVMs). The vulnerability arises because the CopyFile policy only checks the destination path, allowing files to be copied into the shared directory, from where they can be linked to sensitive areas in the guest image. The issue is fixed in Kata Containers version 3.29.0.
Users can upgrade to Kata Containers version 3.29.0, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2026:25200 | redhat-SADP | |
| https://access.redhat.com/security/cve/CVE-2026-41326 | redhat-SADP | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2460859 | redhat-SADP | |
| https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41326.json | redhat-SADP | |
| https://github.com/kata-containers/kata-containers/security/advisories/GHSA-q49m-57vm-c8cc | CISA-ADP | Third Party Advisory |
| http://www.openwall.com/lists/oss-security/2026/05/13/2 | CVE | Mailing ListThird Party Advisory |
| https://github.com/kata-containers/kata-containers/commit/1b9e49eb2763aa6ea6a99b276d3ff5e2c7f658f2 | [email protected] | Patch |
| https://github.com/kata-containers/kata-containers/security/advisories/GHSA-q49m-57vm-c8cc | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1220 | Insufficient Granularity of Access Control | redhat-SADP |
| CWE-61 | UNIX Symbolic Link (Symlink) Following | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| katacontainers confidential containers | >= 0.9.0, < 0.20.0 |
CPE
Remediation
| |
| katacontainers kata containers | >= 3.4.0, < 3.29.0 |
CPE
Remediation
| |
Change History
10 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 24, 2026 | CVE Modified | redhat-SADP |
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 14, 2026 | Initial Analysis | [email protected] |
| May 13, 2026 | CVE Modified | CVE |
| May 4, 2026 | CVE Modified | [email protected] |
| Apr 27, 2026 | CVE Modified | CISA-ADP |
| Apr 24, 2026 | New CVE Received | [email protected] |