Search/CVE-2026-87766
CVE — High

CVE-2026-87766

A flaw was found in bubblewrap. During sandbox setup, creating files or directories under the new root can follow a parent symlink onto the host via /oldroot, writing attacker-chosen paths outside the sandbox as the launching user. This happens before the sandboxed process starts. This issue is GHSA-pxhw-h44j-8pfx. It is fixed in bubblewrap 0.12.0.

CVSS v3.1
8.8 HIGH
EPSS
0.14%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
2
sources referencing this CVE
Intelligence Reports1
1 intelligence report available

Curated threat research and citations from CrowdStrike, Mandiant, Microsoft, and other sources — unlock with Premium.

Upgrade to Premium
CVSS v3.1 Detail
Attack VectorLOCAL
Attack ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
ScopeCHANGED
ConfidentialityHIGH
IntegrityHIGH
AvailabilityHIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Connections
3 relationships
Timeline
disclosure → media coverage
Sep 9, 2026
Disclosure — published as a CVE record.
Sep 17, 2026
ubuntu.com reports: USN-8779-1: Bubblewrap vulnerabilities
Sep 17, 2026
ubuntu.com reports: USN-8779-2: Bubblewrap regression