AUGUST 24, 2026
Live Feed
Back to database
Case File

CVE-2026-10037

HIGH · CVSS 8.8 EPSS 0.12%

Source: NVD + CISA KEV + EPSS · Published 2026-07-08 · Last synced 2026-08-07

CyberRota Analysis

AI-Generated

A high-severity sandbox escape vulnerability in OpenJDK packages on Ubuntu allows compromised applications to execute arbitrary code outside their sandbox. This occurs when the mailcap package is installed, enabling malicious .jar files to be executed if marked as executable. Organizations using Ubuntu with OpenJDK should prioritize patching this vulnerability to mitigate the risk of unauthorized code execution.

CVE
CVE-2026-10037
Severity
HIGH
CVSS
8.8
EPSS
0.12%
Ubuntu

Original NVD Description

A sandbox escape vulnerability exists in the OpenJDK packages provided in Ubuntu. The .jar MIME handlers installed by these packages execute files marked as executable when the mailcap package is installed. A compromised or malicious sandboxed application with access to the OpenURI portal via xdg-desktop-portal-gtk can write a malicious .jar file to the host file system, set its executable bit, and trigger the handler to execute arbitrary code outside of the sandbox environment.