CVE Feed

    Dashboard / CVE / CVE-2026-41326

    CVE-2026-41326

    Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. From v3.4.0 to v3.28.0, an oversight in the CopyFile policy (and perhaps the CopyFile handler) allows untrusted hosts to write to arbitrary locations inside the guest workload image. This can be used to overwrite binaries inside the guest and exfiltrate data from containers; even those running inside CVMs. This vulnerability is fixed in v3.29.0.

    Published:Apr 22, 2026
    Last Modified:May 14, 2026
    EPS:Apr 24, 2026
    EPSS Score:0.00017
    CVSS Score:8.2

    Affected Products

    Vendor
    Katacontainers
    Product
    Confidential Containers
    Vendor
    Katacontainers
    Product
    Kata-containers
    Vendor
    Katacontainers
    Product
    Kata Containers

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High