CVE-2026-1386 describes a symbolic link following vulnerability in the jailer component of Amazon Firecracker versions v1.13.1 and earlier, and v1.14.0. This flaw allows a local host user with write access to pre-created jailer directories to overwrite arbitrary host files via a symlink attack during initialization, provided the jailer runs with root privileges. The vulnerability has a CVSS score of 6.0 (Medium), indicating a local attack vector with low complexity, requiring high privileges to achieve high impact on integrity and availability. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in the KEV catalog, though it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.13.2CPE matchmatch criteria | cpe:2.3:a:amazon:firecracker:*:*:*:*:*:*:*:* | ||
1.14.0CPE matchmatch criteria | cpe:2.3:a:amazon:firecracker:1.14.0:-:*:*:*:*:*:* | ||
1.14.0CPE matchmatch criteria | cpe:2.3:a:amazon:firecracker:1.14.0:dev:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.