top of page
perceptive_background_267k.jpg

An issue was discovered in Canonical Multipass before version 1.16.3. The host-side SFTP server component (sshfs_server), which executes with root privileges on…

Published:

27 mei 2026 om 22:00:00

Alert date:

28 mei 2026 om 19:09:38

Source:

nvd.nist.gov

Click to open the original link from this advisory

Cloud & Virtualization

CVE-2026-49238 affects Canonical Multipass versions before 1.16.3, involving a path containment bypass vulnerability in the host-side SFTP server component (sshfs_server). The vulnerability exists in the validate_path function which performs inadequate path validation without proper normalization of directory traversal sequences. An attacker with root privileges inside a guest VM can inject raw SFTP frames directly into the sshfs_server process via procfs, bypassing the FUSE layer. By exploiting directory traversal sequences that match the allowed mount prefix, the attacker can force the host-side root process to access files outside the designated mount boundary. This results in arbitrary file read access on the host filesystem and enables virtual machine escape attacks.

Technical details

Mitigation steps:

Affected products:

Canonical Multipass

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page