SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-84042

HIGH · CVSS 7.8 EPSS 0.10% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-10 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

A vulnerability in crun allows an attacker to execute malicious payloads with host root privileges when crun is built with libkrun and a container is started in a rootful mode with passt networking enabled. This flaw, introduced in version 1.29, poses a significant risk to systems using affected versions of crun, especially those running untrusted container images. Organizations utilizing crun for container management should prioritize immediate updates to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-84042
Severity
HIGH
CVSS
7.8
EPSS
0.10%

Original NVD Description

A flaw was found in crun. When crun is built with libkrun and a container is started rootful with passt networking (krun.use_passt), crun can execute attacker-controlled payload from the container image with host root privileges. The issue is a regression in crun 1.29. It affects crun >= 1.29