CVE-2026-41163Disclosure

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

bubblewrap is a low-level unprivileged sandboxing tool. From version 0.11.0 to before version 0.11.2, if bubblewrap is installed in setuid mode then the user can use ptrace to attach to bubblewrap and control the unprivileged part of the sandbox setup phase. This allows the attacker to arbitrarily use the privileged operations, and in particular the "overlay mount" operation, allowing the creation of overlay mounts which is otherwise not allowed in the setuid version of bubblewrap. This issue has been patched in version 0.11.2.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 4d ago at 1 mentions (2026-04-25); latest day: 1
  • 5 total mentions across 5 days

Deep dive

Activity timeline5 mentions / 5d
00111Mentions · 2026-04-25: 1Mentions · 2026-04-26: 1Mentions · 2026-04-28: 1Mentions · 2026-05-09: 1Mentions · 2026-05-11: 1Patch / Workaround · 2026-04-28: 1Technical Details · 2026-04-28: 1Technical Details · 2026-05-11: 104-2504-2604-2805-0905-11
Signal classification3 categories
Disclosure
240.0%
General
240.0%
Patch
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-251
Disclosure1
2026-04-261
General1
2026-04-281
Patch1
2026-05-091
General1
2026-05-111
Disclosure1
Full discourse5 posts
  • Open Source Security mailing list@oss_security
    Patch

    CVE-2026-41163: bubblewrap: Privilege escalation if setuid root, via ptrace https://www.openwall.com/lists/oss-security/2026/04/25/1 Vulnerable: bubblewrap >= 0.11.0 if installed setuid Fixed: bubblewrap >= 0.11.2 Not believed to be vulnerable: bubblewrap < 0.11.0

    Post summary

    The advisory details CVE‑2026‑41163 affecting bubblewrap >=0.11.0 that allows privilege escalation via ptrace when setuid root, and notes the fix is in version 0.11.2; no exploitation or PoC is reported.

    01063861
    4.7K followersView on X
  • NanoVMs@nanovms
    Disclosure

    this week in containers don't contain we find yet more bubblewrap bullshit CVE-2026-41163 https://t.co/YqmV1AQLOd

    Post summary

    The tweet announces a new CVE (CVE-2026-41163) affecting bubblewrap and links to additional information, but it does not provide technical details or evidence of exploitation.

    01040324
    2.2K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-41163 📊 Severity: 8.7 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-41163 #CVE-2026-41163 #CVE #High #CyberSecurity #InfoSec https://t.co/KmrRqzcSGD

    Post summary

    The post announces a new vulnerability, CVE‑2026‑41163, with a high severity score and links to the NVD page for further details.

    0000038
    157 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-41163 bubblewrap is a low-level unprivileged sandboxing tool. From version 0.11.0 to before version 0.11.2, if bubblewrap is installed in setuid mode then the user can use … https://www.cve.org/CVERecord?id=CVE-2026-41163

    Post summary

    The snippet references CVE-2026-41163 involving a setuid issue in bubblewrap versions 0.11.0–0.11.1, but offers no PoC, exploit, patch, or detailed technical information.

    0000057
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-41163 bubblewrap https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41163

    Post summary

    The text references CVE‑2026‑41163 and the tool bubblewrap but offers no additional technical or operational details.

    0000043
    4.0K followersView on X

Explore more