A critical vulnerability affecting podman-container-tools/podman versions and Exploitation Status, CVE-2026-94603 with a CVSS score of 10.0, affects podman-container-tools/podman versions from Podman 4.4.0 onward until patched, allowing a hostile container image to override sandboxing restrictions when started with podman run by silently ignoring user input regarding how the container should be created, effectively granting every capability. This flaw can be exploited through public registries and relies on flags like –cap-drop being set by users, which are then quietly undone by the image's own settings. The vulnerability has a significant business impact as teams that pull images from public registries and rely on those flags are at risk of having their limits overridden. The attack vector is remote code execution through untrusted container images, making this flaw particularly concerning for organizations that run untrusted images on hosts with affected versions of Podman.
We recommend you to update Podman to version 6.1.3 or 5.8.8.[/subscribe_to_unlock_form]
A critical vulnerability affecting podman-container-tools/podman versions and Exploitation Status, CVE-2026-94603 with a CVSS score of 10.0, affects podman-container-tools/podman versions from Podman 4.4.0 onward until patched, allowing a hostile container image to override sandboxing restrictions when started with podman run by silently ignoring user input regarding how the container should be created, effectively granting every capability. This flaw can be exploited through public registries and relies on flags like –cap-drop being set by users, which are then quietly undone by the image's own settings. The vulnerability has a significant business impact as teams that pull images from public registries and rely on those flags are at risk of having their limits overridden. The attack vector is remote code execution through untrusted container images, making this flaw particularly concerning for organizations that run untrusted images on hosts with affected versions of Podman.
We recommend you to update Podman to version 6.1.3 or 5.8.8.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]