PatchSiren

apptainer CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM apptainer CVE published 2026-09-15

CVE-2026-48785

A local user can run a container from outside the intended allowlist when Apptainer operates in setuid mode due to plain string-prefix matching in Image.AuthorizedPath. This issue is fixed in version 1.5.1. The vulnerability allows unauthorized container execution, potentially leading to security breaches. System administrators must verify and update Apptainer configurations to prevent exploitation. The f [truncated]