PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-87766 Red Hat CVE debrief

A flaw in bubblewrap allows creating files or directories outside the sandbox via a parent symlink, writing attacker-chosen paths as the launching user before the sandboxed process starts. This issue is fixed in bubblewrap 0.12.0. The vulnerability can lead to potential sandbox escape and unauthorized file creation. Defenders managing systems using bubblewrap for sandboxing should verify exposure and apply the fix. The fix involves updating bubblewrap to version 0.12.0 and reviewing system configurations for potential symlink exploitation paths.

Vendor
Red Hat
Product
Red Hat Enterprise Linux 10
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-09
Original CVE updated
2026-09-22
Advisory published
2026-09-09
Advisory updated
2026-09-22

Who should care

Defenders managing systems using bubblewrap for sandboxing should verify exposure and apply the fix. The vulnerability can lead to potential sandbox escape and unauthorized file creation. It is crucial for defenders to review system configurations and update bubblewrap to version 0.12.0 to prevent exploitation. The fix is a priority for systems using bubblewrap.

Why it matters

CVE-2026-87766 is a high-severity flaw in bubblewrap that allows writing outside the sandbox. Defenders should verify exposure, especially in systems using bubblewrap, and apply the fix in version 0.12.0.

  • Potential for writing arbitrary files as the launching user.
  • Possible sandbox escape and unauthorized file creation.
  • Requires verification of system configurations and bubblewrap versions.
  • Fixing the vulnerability is a priority for systems using bubblewrap.

Technical summary

The bubblewrap flaw allows creating files or directories outside the sandbox via a parent symlink. This can lead to writing attacker-chosen paths outside the sandbox as the launching user before the sandboxed process starts. The vulnerability has a high CVSS score of 8.8 and is classified as HIGH severity. The issue is fixed in bubblewrap 0.12.0 and involves updating the software to prevent potential sandbox escape and unauthorized file creation. The flaw is tracked as GHSA-pxhw-h44j-8pfx and has references in CVE Program, NVD, Red Hat security advisory, Debian bug report, and GitHub release notes.

Defensive priority

Defenders should prioritize verifying exposure and applying the fix, especially in systems using bubblewrap for sandboxing.

Recommended defensive actions

  • Verify if bubblewrap is used in your systems and assess exposure.
  • Apply the fix by updating bubblewrap to version 0.12.0.
  • Review system configurations for potential symlink exploitation paths.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.

Evidence notes

The CVE record and NVD entry provide details on the flaw and its fix. Red Hat and Debian references are available, along with a GitHub advisory and release notes. The vulnerability has a high CVSS score of 8.8 and is classified as HIGH severity. There are references to GHSA-pxhw-h44j-8pfx. The issue is tracked in various sources including CVE Program, NVD, Red Hat security advisory, Debian bug report, and GitHub release notes.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-87766 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-87766

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-87766 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-87766

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.