CVE-2026-1386 MEDIUM

CVE-2026-1386: Arbitrary Host File Overwrite via Symlink in Firecracker Jailer

Weakness CWE-61
Published January 23, 2026
Last update January 23, 2026

CVSS base score

6.0/10
Attack vector Local
Attack complexity Low
Privileges required High
User interaction None
Confidentiality None
Integrity High

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H

What the vulnerability does

01Description

A UNIX symbolic link following issue in the jailer component in Firecracker version v1.13.1 and earlier and 1.14.0 on Linux may allow a local host user with write access to the pre-created jailer directories to overwrite arbitrary host files via a symlink attack during the initialization copy at jailer startup, if the jailer is executed with root privileges. To mitigate this issue, users should upgrade to version v1.13.2 or 1.14.1 or above.

Key dates

02Disclosure timeline

January 23, 2026 CVE published
January 23, 2026 Record updated