CVE-2026-55686
published 2026-06-26CVE-2026-55686: Podman is a tool for managing OCI containers and pods. From 3.0.0 until 5.7.1, running a malicious container image where the WORKDIR path contains a symlink…
PriorityP429medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
0.32%
23.6th percentile
Podman is a tool for managing OCI containers and pods. From 3.0.0 until 5.7.1, running a malicious container image where the WORKDIR path contains a symlink can create a directory or modify ownership on the host filesystem. Modified ownership is less likely to happen as that requires help from an untrusted/malicious process that mutates the host filesystem tree during dereferencing of the WORKDIR path, to trigger a race condition. This vulnerability is fixed in 5.7.1.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ansible-automation-platform-26 | eda-controller-rhel9 | — | — |
| ansible-automation-platform-27 | eda-controller-rhel9 | — | — |
| container-native-virtualization | ocp-virt-validation-checkup-rhel9 | — | — |
| container-tools_rhel8 | podman | — | — |
| github.com | containers_podman_v3 | 0 – 3.4.7 | — |
| github.com | containers_podman_v4 | 0 – 4.9.5 | — |
| github.com | containers_podman_v5 | >= 0 < 5.7.1 | 5.7.1 |
| podman-container-tools | podman | — | — |
| podman_project | podman | — | — |
| podman_project | podman | >= 3.0.0 < 5.7.1 | 5.7.1 |
| quay | quay-builder-rhel8 | — | — |
| quay | quay-builder-rhel9 | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
github.com/containers/podman: Podman: Host filesystem modification via malicious container image WORKDIR symlink
vendor_redhat·2026-06-26·CVSS 5.3
CVE-2026-55686 [MEDIUM] CWE-59 github.com/containers/podman: Podman: Host filesystem modification via malicious container image WORKDIR symlink
github.com/containers/podman: Podman: Host filesystem modification via malicious container image WORKDIR symlink
Podman is a tool for managing OCI containers and pods. From 3.0.0 until 5.7.1, running a malicious container image where the WORKDIR path contains a symlink can create a directory or modify ownership on the host filesystem. Modified ownership is less likely to happen as that requires help from an untrusted/malicious process that mutates the host filesystem tree during dereferencing of the WORKDIR path, to trigger a race condition. This vulnerability is fixed in 5.7.1.
A flaw was found in Podman. A remote attacker can exploit this vulnerability by running a malicious container image where the WORKDIR (working directory) path contains a symbolic link (symlink). This can lead to
GHSA
Podman: WORKDIR symlink traversal vulnerability
ghsa·2026-06-18
CVE-2026-55686 [MEDIUM] CWE-59 Podman: WORKDIR symlink traversal vulnerability
Podman: WORKDIR symlink traversal vulnerability
### Summary
Running a malicous container image where the WORKDIR path contains a symlink can create a directory or modify ownership on the host filesystem. Modified ownership is less likely to happen as that requires help from an untrusted/malicious process that mutates the host filesystem tree during dereferencing of the WORKDIR path, to trigger a race condition.
### Patch
https://github.com/podman-container-tools/podman/commit/d18e44e9abb3bf5b7294aa70806e1368fdddfdd0
### Details
This issue was fixed in podman 5.7.1 (git commit 7ce2e00ab140c11a68301f0b161f51984131a858)
### PoC
The reproducer script _test1.bash_ demonstrates the vulnerability.
The directory `/var/BREAKOUT` is created on the host.
The container process uses the contain
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-55686 podman: Podman: Host filesystem modification via malicious container image WORKDIR symlink [fedora-all]
bugzilla·2026-06-29·CVSS 5.3
CVE-2026-55686 [MEDIUM] CVE-2026-55686 podman: Podman: Host filesystem modification via malicious container image WORKDIR symlink [fedora-all]
CVE-2026-55686 podman: Podman: Host filesystem modification via malicious container image WORKDIR symlink [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Podman is a tool for managing OCI containers and pods. From 3.0.0 until 5.7.1, running a malicious container image where the WORKDIR path contains a symlink can create a directory or modify ownership on the host filesystem. Modified ownership is less likely to happen as that requires help from an untrusted/malicious process that mutates the host filesystem tree during dereferencing of the WORKDIR path, to trigger a race condition. This vulnerability i
Bugzilla
CVE-2026-55686 github.com/containers/podman: Podman: Host filesystem modification via malicious container image WORKDIR symlink
bugzilla·2026-06-26·CVSS 5.3
CVE-2026-55686 [MEDIUM] CVE-2026-55686 github.com/containers/podman: Podman: Host filesystem modification via malicious container image WORKDIR symlink
CVE-2026-55686 github.com/containers/podman: Podman: Host filesystem modification via malicious container image WORKDIR symlink
Podman is a tool for managing OCI containers and pods. From 3.0.0 until 5.7.1, running a malicious container image where the WORKDIR path contains a symlink can create a directory or modify ownership on the host filesystem. Modified ownership is less likely to happen as that requires help from an untrusted/malicious process that mutates the host filesystem tree during dereferencing of the WORKDIR path, to trigger a race condition. This vulnerability is fixed in 5.7.1.
2026-06-26
Published