MEDIUM
apptainer
CVE published 2026-09-15
CVE-2026-48785
A local user can run a container from outside the intended allowlist when Apptainer operates in setuid mode due to plain string-prefix matching in Image.AuthorizedPath. This issue is fixed in version 1.5.1. The vulnerability allows unauthorized container execution, potentially leading to security breaches. System administrators must verify and update Apptainer configurations to prevent exploitation. The f [truncated]