CVE-2026-15801

HIGH CVSS 3.1: 8.0
Updated Sep 21, 2026
Red Hat
Parameter Value
CVSS 8.0 (HIGH)
Type CWE-22 (Path Traversal)
Vendor Red Hat
Public PoC No

A vulnerability was found in CRI-O related to the container checkpoint and restore feature. When CRI-O is configured to restore containers from checkpoint archives, insufficient validation of restore metadata may allow a user with sufficient privileges to perform unintended operations on the host filesystem. Successful exploitation requires that container checkpoint and restore functionality is enabled, which is not the default configuration.

An attacker must also be able to trigger restoration of a container from untrusted checkpoint content.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
High
Difficult to exploit
Privileges Required
High
Admin privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v3.1

Weakness Type (CWE)

Vulnerable Products

red hat:red hat openshift container platform 4