CVE-2026-56857

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

On Windows, when the target of Root.Mkdir or Root.MkdirAll is a junction pointing to an empty location, the operation can create a directory at the junction target even when that target is located outside the root. This only applies to operations where the last path component is a junction (path/to/junction, but not path/junction/target).

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1386

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked 1d ago at 1 mentions (2026-10-09); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-10-09: 1Mentions · 2026-10-10: 110-0910-10
Referenced assets1 URL
By indicator
Full discourse2 posts
  • SecAlerts@SecAlertsCo

    🪟 Go on Windows: CVE-2026-56857 is critical (CVSS 9.8). Root.Mkdir/MkdirAll can follow junctions outside the root boundary, creating dirs in unintended locations. Patch Go now. #golang #cybersecurity #ciso #vulnerabilities #mssp https://secalerts.co/vulnerability/CVE-2026-56857?utm_campaign=x https://t.co/hMBPZCQ4tc

    1102079
    894 followersView on X
  • Upwind Security MDR@UpwindMDR

    🚨Critical - Go Windows Root.Mkdir* Junction Traversal Outside Root (CVE-2026-56857) On Windows, Go's os.Root.Mkdir and os.Root.MkdirAll can follow a junction when the final path component is the junction itself (e.g., path/to/junction), causing directory creation at the junction target even if it escapes the intended root. This enables write/create outside sandboxed roots. Non-Windows builds are not affected. 👉Affected: Go stdlib (os.Root.Mkdir/os.Root.MkdirAll on Windows)

    0000040
    315 followersView on X

Explore more