CVE-2026-1386Disclosure(amazon / firecracker)

LOWCVSS 6.0 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A UNIX symbolic link following issue in the jailer component in Firecracker version v1.13.1 and earlier and 1.14.0 on Linux may allow a local host user with write access to the pre-created jailer directories to overwrite arbitrary host files via a symlink attack during the initialization copy at jailer startup, if the jailer is executed with root privileges. To mitigate this issue, users should upgrade to version v1.13.2 or 1.14.1 or above.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-61

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • firecracker

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-02-14); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
firecracker

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-14: 1Mentions · 2026-02-18: 1Technical Details · 2026-02-14: 1Technical Details · 2026-02-18: 102-1402-18
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-02-141
Disclosure1
2026-02-181
General1
Full discourse2 posts
  • ‏⧢ ⦟ ⧢ ‏ ᅠ ᅠ ⧢ ⦟ ⧢ ᅠ‏ ᅠ ⧢ ⦟ ⧢ ⥋ ᅠᅠ ᅠ⧢⧟⧢ ᅠᅠᅠ‏ᅠᅠᅠ‏@EVEZ666
    General

    Firecracker-specific surface: CVE-2026-1386: Jailer symlink → arbitrary host file overwrite CVE-2019-18960: virtio-vsock → r/w in VMM process io_uring: still in seccomp allowlist, bypasses filtering The Jailer IS the last defense. If it falls, nothing's left.

    Post summary

    The snippet enumerates two Firecracker CVEs with technical impact details, but provides no proof of concept, exploit code, patch, or evidence of active exploitation.

    1000038
    1.5K followersView on X
  • Alex Pulver@alex_pulver
    Disclosure

    CVE-2026-1386 - Arbitrary Host File Overwrite via Symlink in Firecracker Jailer https://aws.amazon.com/security/security-bulletins/rss/2026-003-aws/

    Post summary

    AWS discloses CVE-2026-1386, a host file overwrite vulnerability in Firecracker Jailer via symlink, with details linked in its security bulletin.

    0000039
    376 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appamazonfirecracker---
Appamazonfirecracker1.14.0--
Appamazonfirecracker1.14.0--

Explore more