https://seclists.org/oss-sec/2026/q2/514: CVE-2026-41326: Kata Containers: CopyFile Policy Subversion via Symlinks
Published May 13, 2026
·Updated
Affected Software
1 affected component
Kata Containers Kata Containers>=3.4.0<=3.28.0
CVE-2026-41326 is considered a high severity vulnerability due to its potential for policy subversion via symlinks.
To fix CVE-2026-41326, update to the latest version of Kata Containers that includes the necessary security patches.
CVE-2026-41326 affects deployments of Kata Containers that utilize file copy operations involving symlink handling.
The impact of CVE-2026-41326 could allow an attacker to bypass security policies and access restricted files.
CVE-2026-41326 was disclosed on May 13, 2026.