CVE Feed

    Dashboard / CVE / CVE-2026-24835

    CVE-2026-24835

    Podman Desktop is a graphical tool for developing on containers and Kubernetes. A critical authentication bypass vulnerability in Podman Desktop prior to version 1.25.1 allows any extension to completely circumvent permission checks and gain unauthorized access to all authentication sessions. The `isAccessAllowed()` function unconditionally returns `true`, enabling malicious extensions to impersonate any user, hijack authentication sessions, and access sensitive resources without authorization. This vulnerability affects all versions of Podman Desktop. Version 1.25.1 contains a patch for the issue.

    Published:Jan 28, 2026
    Last Modified:Apr 18, 2026
    EPS:Jan 28, 2026
    EPSS Score:0.00067
    CVSS Score:7.1

    Affected Products

    Vendor
    Linuxfoundation
    Product
    Podman Desktop
    Vendor
    Podman-desktop
    Product
    Podman-desktop

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High