CVE-2026-46680

Aliases:GHSA-fqw6-gf59-qr4wGO-2026-5378
PUBLISHED
Published: 01 Jul 2026, 17:40
Last modified:03 Jul 2026, 03:56

Vulnerability Summary

Overall Risk (default)
medium
29/100
CVSS Score
7.3 HIGH
v4.0 (cve.org)
EPSS Score
0.22% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

01 Jul 2026, 17:40
Published
Vulnerability first disclosed
03 Jul 2026, 03:56
Last Modified
Vulnerability information updated

Description

containerd is an open-source container runtime. In versions prior to 1.7.32, 2.0.9, 2.2.4 and 2.3.1, containers launched with a numeric User directive that cannot be parsed as a 32-bit integer are incorrectly treated as a username, leading to runAsNonRoot evasion. If a crafted image provides an /etc/passwd file mapping this large numeric string to root, the container ultimately runs as root (UID 0). This allows the Kubernetes runAsNonRoot restriction to be bypassed, causing unexpected behavior for environments that require containers to run as a non-root user. This issue has been fixed in versions 1.7.32, 2.0.9, 2.2.4 and 2.3.1.

CVSS Metrics

  • v4.0HIGHScore: 7.3CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
  • v3.1HIGHScore: 7.8CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS Trends

Current EPSS score: 0.22% Percentile: 13%

Techniques & Countermeasures

  • CWE-269Improper Privilege Management

    The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Systems

  • containerdcontainerd

    < 1.7.32 | ≥ 2.0.4, < 2.0.9 | ≥ 2.0.10, < 2.2.4 | ≥ 2.2.5, < 2.3.1

  • github.com/containerdcontainerd

    ≥ 1.7.27, < 1.7.32

  • github.com/containerd/containerdv2

    ≥ 2.0.4, < 2.0.9 | ≥ 2.1.0-beta.0, < 2.2.4 | ≥ 2.3.0-beta.0, < 2.3.1

References (3)