MinorCritical vulnerability
CVE-2026-62146 (CVSS 7.8)
NVD · officialPublished Sep 30, 2026Risk 23/100
A trust-boundary flaw in CRI-O's sandbox state persistence allows attacker-influenced pod metadata to overwrite CRI-O's own reserved sandbox bookkeeping; once reloaded as trusted after a restart, a later container recreate in that sandbox can expose a host-side runtime-management resource inside the container, enabling container escape.
Technical details
CVSS
7.8
AV:LocalAC:HighPR:LowUI:NoneC:HighI:HighA:High
Evidence and sources
This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source