CVE-2026-32677
Awaiting Analysis Awaiting Analysis - Queue

Path Traversal in Gaudi Container Runtime

Vulnerability report for CVE-2026-32677, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-12

Assigner: Intel Corporation

Description

Path traversal for some gaudi-container-runtime before version 1.24.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires passive user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-12
Generated
2026-09-01
AI Q&A
2026-08-12
EPSS Evaluated
2026-08-30
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
intel gaudi_container_runtime to 1.24.0 (exc)
intel gaudi-container-runtime to 1.24.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a path traversal vulnerability in gaudi-container-runtime versions before 1.24.0. It allows an authenticated user with local access to potentially escalate privileges by exploiting low-complexity conditions. The attack requires passive user interaction and no special internal knowledge.

Detection Guidance

This CVE describes a path traversal vulnerability in gaudi-container-runtime before version 1.24.0. Detection requires checking the installed version of the runtime. Use commands like 'gaudi-container-runtime --version' or inspect package managers (e.g., 'dpkg -l | grep gaudi-container-runtime' for Debian-based systems). If the version is below 1.24.0, the system is vulnerable.

Impact Analysis

An attacker could gain elevated privileges on the system, leading to potential compromise of confidentiality, integrity, and availability. This may result in unauthorized access, data manipulation, or system disruption.

Compliance Impact

The vulnerability may impact confidentiality, integrity, and availability of systems, which are critical for compliance with standards like GDPR and HIPAA. High confidentiality and integrity impacts could lead to unauthorized data access or modification, violating GDPR's data protection principles or HIPAA's safeguards for protected health information.

Mitigation Strategies

Update gaudi-container-runtime to version 1.24.0 or later to address the path traversal vulnerability. Ensure all systems using this runtime apply the patch immediately to prevent potential privilege escalation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-32677. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart