CVEFinder.io

CVE-2026-55686

đŸ”ļ medium
🔍 Scan for this CVE
Summary

Podman is a tool for managing OCI containers and pods. From 3.0.0 until 5.7.1, running a malicious container image where the WORKDIR path contains a symlink can create a directory or modify ownership on the host filesystem. Modified ownership is less likely to happen as that requires help from an untrusted/malicious process that mutates the host filesystem tree during dereferencing of the WORKDIR path, to trigger a race condition. This vulnerability is fixed in 5.7.1.

CVSS Score
5.3
Medium
EPSS Score
-
Published Date
2026-06-26
First Seen: 2026-06-27
📊 Relative Risk Intelligence

This CVE is Lower Risk - more severe than 19.7% of all 330,193 vulnerabilities in our database.

#265,260
Below average severity
Severity Percentile
đŸŽ¯ CISA SSVC Assessment Updated: Jun 26, 2026
🔍 Exploitation Status
Poc
Proof-of-concept available
âš™ī¸ Automatable
YES
Can be exploited automatically
đŸ’Ĩ Technical Impact
Partial
Limited system impact
SSVC data provided by CISA
Last Modified 2026-06-26
CVSS Vector 3.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CWE IDs (Weakness Types)

đŸ“Ļ Affected Products 1

🔗 References 2

🔗 Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2024-3056 âš ī¸ high 7.7 0.4 A flaw was found in Podman. This issue may allow an attacker to create a specially crafted container that, when configur... 2024-08-02
CVE-2023-0778 đŸ”ļ medium 6.8 0.1 A Time-of-check Time-of-use (TOCTOU) flaw was found in podman. This issue may allow a malicious user to replace a normal... 2023-03-27
CVE-2022-4122 đŸ”ļ medium 5.3 0.2 A vulnerability was found in buildah. Incorrect following of symlinks while reading .containerignore and .dockerignore r... 2022-12-08
CVE-2022-4123 â„šī¸ low 3.3 0.0 A flaw was found in Buildah. The local path and the lowest subdirectory may be disclosed due to incorrect absolute path ... 2022-12-08
CVE-2022-2989 âš ī¸ high 7.1 0.0 An incorrect handling of the supplementary groups in the Podman container engine might lead to the sensitive information... 2022-09-13
CVE-2022-2738 âš ī¸ high 7.5 0.4 The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrec... 2022-09-01
These CVEs affect the same products