Aller au contenu principal
HIGH

CVE-2026-82430

CVSS v3

7.8

HIGH

Score EPSS

0.1 %

probabilité d’exploitation au 2026-09-28

CISA KEV

Non

exploitation connue

Exploitation

—

statut SSVC

Description

Description When launching a Docker or OCI worker, the setuid-root `worker-launcher` first changes ownership of the entire worker directory to the untrusted topology user, and only afterwards reads and acts on the command file that the supervisor wrote into that same directory. The file is opened without `O_NOFOLLOW` and without re-verifying its owner, so between the ownership change and the read the tenant can replace its contents. For the Docker path the parsed command is executed with real

Détails techniques

Publiée le
2026-09-14
Dernière modification
2026-09-14

Questions fréquentes

Qu’est-ce que CVE-2026-82430 ?

Description When launching a Docker or OCI worker, the setuid-root `worker-launcher` first changes ownership of the entire worker directory to the untrusted topology user, and only afterwards reads and acts on the command file that the supervisor wrote into that same directory. The file is opened without `O_NOFOLLOW` and without re-verifying its owner, so between the ownership change and the read the tenant can replace its contents. For the Docker path the parsed command is executed with real

CVE-2026-82430 est-elle activement exploitée ?

Aucune exploitation active de CVE-2026-82430 n’est confirmée. Son score EPSS était de 0.1 % au 2026-09-28, soit la probabilité estimée d’exploitation dans les 30 prochains jours.

Quel est le score CVSS de CVE-2026-82430 ?

CVE-2026-82430 a un score de base CVSS v3 de 7.8 (gravité HIGH).

CVE-2026-82430 touche-t-elle votre environnement ?

Utilisez isMalicious pour vérifier si l’une de vos IP ou l’un de vos domaines est associé aux IOC de cette vulnérabilité.

Sans carte bancaire · 500 vérifications gratuites par mois · Clé API gratuite