CVE-2026-62146
Received Received - Intake

CRI-O Sandbox State Persistence Flaw Enables Container Escape

Vulnerability report for CVE-2026-62146, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: redhat-SADP

Description

A trust-boundary flaw in CRI-O's sandbox state persistence allows attacker-influenced pod metadata to overwrite CRI-O's own reserved sandbox bookkeeping; once reloaded as trusted after a restart, a later container recreate in that sandbox can expose a host-side runtime-management resource inside the container, enabling container escape.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 7 associated CPEs
Vendor Product Version / Range
redhat cri-o *
redhat cri-o to 1.34.11 (inc)
redhat cri-o to 1.35.6 (inc)
redhat cri-o to 1.36.3 (inc)
redhat cri-o 1.34
redhat cri-o 1.35
redhat cri-o 1.36

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-501 The product mixes trusted and untrusted data in the same data structure or structured message.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-62146 is a trust-boundary flaw in CRI-O's sandbox state persistence. Attackers can craft pod annotations to overwrite CRI-O's internal sandbox metadata, which is stored alongside untrusted pod data without proper separation. When CRI-O restarts or the node reboots, the poisoned state is reloaded as trusted. A subsequent container recreation in the same sandbox can then expose host-side runtime resources inside the container, enabling container escape and potential host compromise.

Detection Guidance

Detecting this vulnerability requires checking for suspicious pod annotations or labels with the io.kubernetes.cri-o prefix, monitoring for anomalous container mounts after CRI-O restarts, and reviewing pod creation events. Inspect pod metadata for unexpected annotations or labels that could poison sandbox state. Check CRI-O logs for errors related to sandbox state persistence or container recreation failures.

Impact Analysis

If exploited, this vulnerability allows an attacker to escape container isolation and gain host-level privileges. This could lead to reading sensitive host data, modifying host resources, disrupting other containers, or taking full control of the node. Exploitation requires local node access and the ability to create pods, followed by a CRI-O restart or node reboot.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements in GDPR and HIPAA. A container escape could expose protected health information or personal data, resulting in compliance breaches, regulatory penalties, and loss of trust. Organizations must patch or mitigate to maintain compliance.

Mitigation Strategies

Immediately upgrade CRI-O to patched versions (1.34.12, 1.35.7, or 1.36.4). Wipe all running containers on affected nodes during upgrade. Implement an admission webhook to reject pods with io.kubernetes.cri-o annotations or labels. Restrict pod creation and annotation updates via RBAC or admission policies. Minimize unnecessary CRI-O restarts or node reboots to reduce exposure windows.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-62146. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart