CVE-2026-62146
HIGHDescription
A trust-boundary flaw in CRI-O's sandbox state persistence allows attacker-influenced pod metadata to overwrite CRI-O's own reserved sandbox bookkeeping; once reloaded as trusted after a restart, a later container recreate in that sandbox can expose a host-side runtime-management resource inside the container, enabling container escape.
Is your site exposed to CVE-2026-62146?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
EPSS — Exploit Prediction
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
Weakness Type (CWE)
References
Frequently Asked Questions
What is CVE-2026-62146? +
How severe is CVE-2026-62146? +
How do I check if I'm vulnerable to CVE-2026-62146? +
Related Vulnerabilities
Improper validation of non-secure (NS) pointers in multiple TrustZone-M non-secure callable (NSC) entry functions allows an attacker executing in the …
go-gh is a collection of Go modules to make authoring GitHub CLI extensions easier. A security vulnerability has been identified …
An unauthenticated remote attacker can post a malicious ID to the MQTT Broker results in the creation of a new …
Visual Studio Code Python Extension Remote Code Execution Vulnerability
Artemis Java Test Sandbox versions before 1.8.0 are vulnerable to a sandbox escape when an attacker includes class files in …
Trust boundary violation in Windows Attestation allows an authorized attacker to elevate privileges locally.