CVE-2026-41326General(katacontainers / confidential_containers)

LOWCVSS 8.2 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. From v3.4.0 to v3.28.0, an oversight in the CopyFile policy (and perhaps the CopyFile handler) allows untrusted hosts to write to arbitrary locations inside the guest workload image. This can be used to overwrite binaries inside the guest and exfiltrate data from containers; even those running inside CVMs. This vulnerability is fixed in v3.29.0.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-61CWE-1220

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • confidential_containers
  • kata_containers

Threat summary

  • Public PoC is present in monitored signal
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • General: 2 classified signals
  • Disclosure: 2 classified signals
  • Peaked 3d ago at 1 mentions (2026-04-24); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Products
confidential_containerskata_containers

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-04-24: 1Mentions · 2026-04-25: 1Mentions · 2026-05-04: 1Mentions · 2026-05-15: 1PoC Mentioned / Linked · 2026-05-15: 1Technical Details · 2026-04-25: 1Technical Details · 2026-05-04: 1Technical Details · 2026-05-15: 104-2404-2505-0405-15
Signal classification2 categories
General
250.0%
Disclosure
250.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-241
General1
2026-04-251
General1
2026-05-041
Disclosure1
2026-05-151
Disclosure1
Full discourse4 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-41326: Kata Containers: CopyFile Policy Subversion via Symlinks https://www.openwall.com/lists/oss-security/2026/05/13/2 allows untrusted hosts to write to arbitrary locations inside the guest workload image. This can be used to overwrite binaries inside the guest and exfiltrate data from containers.

    Post summary

    The text announces CVE-2026-41326, a Kata Containers flaw that allows untrusted hosts to overwrite files inside a guest via symlinks, potentially enabling binary replacement and data exfiltration, with a reference link for more details.

    01021430
    4.7K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Kata Containers, CopyFile Policy Subversion via Symlinks, #CVE-2026-41326 (High) https://dailycve.com/kata-containers-copyfile-policy-subversion-via-symlinks-cve-2026-41326-high/

    Post summary

    This post announces a new high‑severity CVE‑2026-41326 affecting Kata Containers, describing a CopyFile policy subversion via symlinks.

    0000036
    191 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-41326 Arbitrary File Write in Kata Containers CopyFile Policy Versions 3.4.0-3.28.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41326

    Post summary

    The entry identifies CVE-2026-41326 as an arbitrary file write flaw affecting Kata Containers policy versions 3.4.0-3.28.0, but offers no PoC, exploit, or patch details.

    0000055
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-41326 Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. From v3.4.0 to v3.… https://www.cve.org/CVERecord?id=CVE-2026-41326

    Post summary

    The text references CVE-2026-41326 for Kata Containers but provides no actionable information about the vulnerability, exploitation, or mitigations.

    0000081
    57.2K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appkatacontainersconfidential_containers---
Appkatacontainerskata_containers---

Explore more