---
id: CVE-2026-62146
title: >-
  A trust-boundary flaw in CRI-O's sandbox state persistence allows
  attacker-influenced pod metadata to overwrite CRI-O's own reserved sandbox
  bookkeeping; once reloaded as trusted after a restart, a later container
  recreate in that sandbo…
summary: >-
  A trust-boundary flaw in CRI-O's sandbox state persistence allows
  attacker-influenced pod metadata to overwrite CRI-O's own reserved sandbox
  bookkeeping; once reloaded as trusted after a restart, a later container
  recreate in that sandbo…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-501
vendor: Red Hat
product: cri-o
affected:
  - cri-o (all versions)
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T12:17:13.617'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-62146'
references:
  - url: 'https://access.redhat.com/security/cve/CVE-2026-62146'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2499618'
    label: secalert@redhat.com
  - url: 'https://github.com/cri-o/cri-o/security/advisories/GHSA-6wmc-5877-hgc9'
    label: secalert@redhat.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-30T12:02:58.586Z'
---

## Overview

A trust-boundary flaw in CRI-O's sandbox state persistence allows attacker-influenced pod metadata to overwrite CRI-O's own reserved sandbox bookkeeping; once reloaded as trusted after a restart, a later container recreate in that sandbox can expose a host-side runtime-management resource inside the container, enabling container escape.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
