CVE-2026-41163
Last modified
CVE-2026-41163 is a high-severity vulnerability rated 8.7/10 on the CVSS scale. bubblewrap is a low-level unprivileged sandboxing tool. From version 0.11.0 to before version 0.11.2, if bubblewrap is installed in setuid mode then the user can use ptrace to attach to bubblewrap and control the unprivileged part of the sandbox setup phase. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
bubblewrap is a low-level unprivileged sandboxing tool. From version 0.11.0 to before version 0.11.2, if bubblewrap is installed in setuid mode then the user can use ptrace to attach to bubblewrap and control the unprivileged part of the sandbox setup phase. This allows the attacker to arbitrarily use the privileged operations, and in particular the "overlay mount" operation, allowing the creation of overlay mounts which is otherwise not allowed in the setuid version of bubblewrap. This issue has been patched in version 0.11.2.
Metrics
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-41163?
How severe is CVE-2026-41163?
How do I fix CVE-2026-41163?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-41157A web page that contains unusual WebGPU content loaded into …9.8
- CVE-2026-41158Software installed and run as a non-privileged user may cond…7.8
- CVE-2026-41159Mermaid is a JavaScript tool that uses Markdown-inspired tex…5.3
- CVE-2026-4116Improper handling of Unicode encoding in SonicWall SMA1000 s…7.2
- CVE-2026-41160EspoCRM is an open source customer relationship management a…4.3
- CVE-2026-41161Sync-in Server is a secure, open-source platform for file st…5.3
- CVE-2026-41164nuts-node is the reference implementation of the Nuts specif…4.4
- CVE-2026-41166OpenRemote is an open-source internet-of-things platform. Pr…7
- CVE-2026-41167Jellystat is a free and open source Statistics App for Jelly…9.1
- CVE-2026-41168pypdf is a free and open-source pure-python PDF library. An …5.3
- CVE-2026-4117The CalJ plugin for WordPress is vulnerable to Missing Autho…5.3
- CVE-2026-41170Squidex is an open source headless content management system…7.2
Are you affected by CVE-2026-41163?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
