Improper access control in Podman - CVE-2026-94603

 

Improper access control in Podman - CVE-2026-94603

Published: September 29, 2026


Vulnerability identifier: #VU152868
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-94603
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise confidentiality, integrity, and availability.

The vulnerability exists due to improper handling of checkpoint image annotations in the podman run command when processing an image containing the io.podman.annotations.checkpoint.runtime.name annotation. A remote attacker can provide a crafted image with this annotation to cause Podman to disregard user-supplied sandboxing options.


Affected software

Podman

How to mitigate CVE-2026-94603

Install security update from vendor's website.

Podman - addressed in versions 5.8.8, 6.1.3

External References

Related Security Bulletins