CVE-2026-30892 is a high-severity privilege escalation vulnerability (CVSS 7.8) affecting crun_project crun versions 1.19 through 1.26. It stems from incorrect parsing of the `crun exec -u` option, where the value '1' is misinterpreted as UID 0 and GID 0, rather than UID 1. This allows a local attacker with low privileges to execute processes with root privileges inside a container, leading to high impact on confidentiality, integrity, and availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this issue. The vulnerability is patched in crun version 1.27.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.19, < 1.27CPE matchmatch criteria | cpe:2.3:a:crun_project:crun:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.