Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-33414

29
FAUCET Score

OVERVIEW Podman versions 4.8.0 through 5.8.1 contain a command injection vulnerability in the HyperV machine backend where unsanitized VM image paths enable PowerShell subexpression injection. An attacker controlling the VM image path through a crafted machine name or image directory can execute arbitrary PowerShell commands. The vulnerability is exclusive to Windows systems using the HyperV backend and has been patched in version 5.8.2. SEVERITY The vulnerability presents a high-impact threat with a local attack vector and low complexity. An attacker with the ability to influence VM image paths can achieve SYSTEM-level code execution on typical Windows installations, representing complete system compromise. The relatively low EPSS score of 0.0004 suggests limited prevalence in current threat landscapes, though the potential impact remains severe for affected deployments. EXPLOITATION STATUS There is no evidence of active exploitation in the wild, as indicated by the CVE's inactive status on threat feeds and its absence from the Known Exploited Vulnerabilities catalog. No public exploit code availability is documented. Community attention appears limited given the specialized nature of the vulnerability, restricted platform scope, and the availability of a timely patch.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.8.0, < 5.8.2CPE matchmatch criteria
cpe:2.3:a:podman_project:podman:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

4.0MEDIUM

CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
LOCAL
Attack Complexity
HIGH
Attack Requirements
NONE
Privileges Required
HIGH
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
UNREPORTED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.61%
Probability of exploitation in next 30 days
EPSS Percentile
45.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0061 is in the 84th percentile among its peer group of 1,525 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
gopatch availablevia ghsa
Product: github.com/containers/podman/v5Fixed in: 5.8.2

Vendor Advisories (1)

goGHSA-hc8w-h2mf-hp59medium

PowerShell Command Injection in Podman HyperV Machine

Apr 14, 2026

References

access.redhat.com / errata/RHSA-2026:8211
access.redhat.com / security/cve/CVE-2026-33414
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-33414.json
github.com / containers/podman/commit/571c842bd357ee626019ea97d030fb772fc654ed
Patch
github.com / containers/podman/security/advisories/GHSA-hc8w-h2mf-hp59
PatchVendor Advisory