{"api_version":"1","generated_at":"2026-10-06T21:46:27+00:00","cve":"CVE-2026-76061","urls":{"html":"https://cve.report/CVE-2026-76061","api":"https://cve.report/api/cve/CVE-2026-76061.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-76061","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-76061"},"summary":{"title":"Cri-o: cri-o: bind_mount_prefix intermediate-symlink prefix bypass","description":"A flaw was found in CRI-O's `bind_mount_prefix` handling. When configured with a non-empty `bind_mount_prefix`, a malicious container or local attacker could use a Container Runtime Interface (CRI) hostPath containing an intermediate absolute symlink. This could cause the bind mount source to resolve outside the intended prefixed root, potentially leading to unauthorized access to files or privilege escalation on the host system.","state":"PUBLISHED","assigner":"redhat","published_at":"2026-10-06 20:17:29","updated_at":"2026-10-06 20:17:29"},"problem_types":["CWE-59","CWE-59 Improper Link Resolution Before File Access ('Link Following')"],"metrics":[{"version":"3.1","source":"secalert@redhat.com","type":"Primary","score":"5.5","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"5.5","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L","data":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":5.5,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"HIGH","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L","version":"3.1"}}],"references":[{"url":"https://github.com/cri-o/cri-o/commit/01f90366dc8c8db0df32b4aae7fd067c1eddbb70","name":"https://github.com/cri-o/cri-o/commit/01f90366dc8c8db0df32b4aae7fd067c1eddbb70","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://access.redhat.com/security/cve/CVE-2026-76061","name":"https://access.redhat.com/security/cve/CVE-2026-76061","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2520330","name":"https://bugzilla.redhat.com/show_bug.cgi?id=2520330","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/cri-o/cri-o/commit/d6f58973acfcae93ecc039e0297fbe5f2548b46b","name":"https://github.com/cri-o/cri-o/commit/d6f58973acfcae93ecc039e0297fbe5f2548b46b","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/cri-o/cri-o/commit/6d08a9a60ecfabdb3cbea0c8d698e31f1f01cb40","name":"https://github.com/cri-o/cri-o/commit/6d08a9a60ecfabdb3cbea0c8d698e31f1f01cb40","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-76061","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-76061","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","version":"","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","version":"","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","version":"","platforms":[]}],"timeline":[{"source":"CNA","time":"2026-08-13T00:00:00.000Z","lang":"en","value":"Reported to Red Hat."},{"source":"CNA","time":"2026-10-06T16:13:57.960Z","lang":"en","value":"Made public."}],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"collectionURL":"https://github.com/cri-o/cri-o","defaultStatus":"unaffected","packageName":"cri-o","versions":[{"lessThan":"1.34.14","status":"affected","version":"0","versionType":"semver"},{"lessThan":"1.35.9","status":"affected","version":"1.35.0","versionType":"semver"},{"lessThan":"1.36.6","status":"affected","version":"1.36.0","versionType":"semver"},{"lessThan":"1.37.1","status":"affected","version":"1.37.0","versionType":"semver"}]},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:openshift:4"],"defaultStatus":"affected","packageName":"cri-o","product":"Red Hat OpenShift Container Platform 4","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:openshift:4"],"defaultStatus":"affected","packageName":"openshift/ose-rhel-coreos-8","product":"Red Hat OpenShift Container Platform 4","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:openshift:4"],"defaultStatus":"affected","packageName":"openshift/ose-rhel-coreos-9","product":"Red Hat OpenShift Container Platform 4","vendor":"Red Hat"}],"datePublic":"2026-10-06T16:13:57.960Z","descriptions":[{"lang":"en","value":"A flaw was found in CRI-O's `bind_mount_prefix` handling. When configured with a non-empty `bind_mount_prefix`, a malicious container or local attacker could use a Container Runtime Interface (CRI) hostPath containing an intermediate absolute symlink. This could cause the bind mount source to resolve outside the intended prefixed root, potentially leading to unauthorized access to files or privilege escalation on the host system."}],"metrics":[{"other":{"content":{"namespace":"https://access.redhat.com/security/updates/classification/","value":"Moderate"},"type":"Red Hat severity rating"}},{"cvssV3_1":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":5.5,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"HIGH","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L","version":"3.1"},"format":"CVSS"}],"problemTypes":[{"descriptions":[{"cweId":"CWE-59","description":"Improper Link Resolution Before File Access ('Link Following')","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-10-06T19:56:48.097Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"tags":["vdb-entry","x_refsource_REDHAT"],"url":"https://access.redhat.com/security/cve/CVE-2026-76061"},{"name":"RHBZ#2520330","tags":["issue-tracking","x_refsource_REDHAT"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2520330"},{"url":"https://github.com/cri-o/cri-o/commit/01f90366dc8c8db0df32b4aae7fd067c1eddbb70"},{"url":"https://github.com/cri-o/cri-o/commit/6d08a9a60ecfabdb3cbea0c8d698e31f1f01cb40"},{"url":"https://github.com/cri-o/cri-o/commit/d6f58973acfcae93ecc039e0297fbe5f2548b46b"}],"timeline":[{"lang":"en","time":"2026-08-13T00:00:00.000Z","value":"Reported to Red Hat."},{"lang":"en","time":"2026-10-06T16:13:57.960Z","value":"Made public."}],"title":"Cri-o: cri-o: bind_mount_prefix intermediate-symlink prefix bypass","x_generator":{"engine":"cvelib 1.8.0"},"x_redhatCweChain":"CWE-59: Improper Link Resolution Before File Access ('Link Following')"}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2026-76061","datePublished":"2026-10-06T19:24:30.457Z","dateReserved":"2026-08-18T20:55:51.671Z","dateUpdated":"2026-10-06T19:56:48.097Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-10-06 20:17:29","lastModifiedDate":"2026-10-06 20:17:29","problem_types":["CWE-59","CWE-59 Improper Link Resolution Before File Access ('Link Following')"],"metrics":{"cvssMetricV31":[{"source":"secalert@redhat.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:L","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":1.3,"impactScore":3.7}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"76061","Ordinal":"1","Title":"Cri-o: cri-o: bind_mount_prefix intermediate-symlink prefix bypa","CVE":"CVE-2026-76061","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"76061","Ordinal":"1","NoteData":"A flaw was found in CRI-O's `bind_mount_prefix` handling. When configured with a non-empty `bind_mount_prefix`, a malicious container or local attacker could use a Container Runtime Interface (CRI) hostPath containing an intermediate absolute symlink. This could cause the bind mount source to resolve outside the intended prefixed root, potentially leading to unauthorized access to files or privilege escalation on the host system.","Type":"Description","Title":"Cri-o: cri-o: bind_mount_prefix intermediate-symlink prefix bypa"}]}}}