Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2020-5291

25
FAUCET Score

CVE-2020-5291 describes a privilege escalation vulnerability in Bubblewrap (bwrap) versions prior to 0.4.1. When bwrap is installed in setuid mode and unprivileged user namespaces are supported by the kernel, an attacker can leverage the --userns2 option to maintain root privileges while being traceable, ultimately leading to root access. This primarily affects specific configurations of Debian, Arch (with linux-hardened), and CentOS (Flatpak COPR) where unprivileged user namespaces are enabled. The vulnerability carries a CVSS v3.1 score of 7.8 (High), indicating a local attack vector with low attack complexity and requiring low privileges, but resulting in high impact to confidentiality, integrity, and availability. The EPSS score is very low, suggesting a minimal likelihood of exploitation in the wild. There is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are also minimal, indicating a low level of public attention.

Impacted Technologies

VendorProductVersion(s)CPE
< 0.4.1CPE matchmatch criteria
cpe:2.3:a:projectatomic:bubblewrap:*:*:*:*:*:*:*:*
10.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:archlinux:arch_linux:-:*:*:*:*:*:*:*
7.0CPE matchmatch criteria
cpe:2.3:o:centos:centos:7.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.2HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
0.8
Impact Score
5.8
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.91%
Probability of exploitation in next 30 days
EPSS Percentile
56.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
This CVE's current EPSS score of 0.0091 is in the 90th percentile among its peer group of 16,974 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

github_advisorypatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: 16996-16820Fixed in: 0.3.0-5
microsoftpatch availablevia msrc
Product: cm1 bubblewrap 0.3.0-5 on CBL Mariner 1.0Fixed in: 0.3.0-5
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 x64Fixed in: 0.3.0-5
microsoftpatch availablevia msrc
Product: CBL Mariner 1.0 ARMFixed in: 0.3.0-5

Vendor Advisories (3)

microsoft2020-Sep/CVE-2020-5291

CVE-2020-5291

Sep 8, 2020
redhatCVE-2020-5291Moderate

bubblewrap: privilege escalation in some kernel configurations

Mar 31, 2020
microsoft2020-Mar/CVE-2020-5291Important

Privilege escalation in setuid mode via user namespaces in Bubblewrap

Mar 10, 2020

References

github.com / containers/bubblewrap/commit/1f7e2ad948c051054b683461885a0215f1806240
PatchThird Party Advisory
github.com / containers/bubblewrap/security/advisories/GHSA-j2qp-rvxj-43vj
MitigationThird Party Advisory