


Perceptive Security
SOC/SIEM Consultancy

An issue was discovered in Canonical Multipass before version 1.16.3. The host-side SFTP server component (sshfs_server), which executes with root privileges on…
Published:
27 mei 2026 om 22:00:00
Alert date:
28 mei 2026 om 19:09:38
Source:
nvd.nist.gov
Cloud & Virtualization
CVE-2026-49238 affects Canonical Multipass versions before 1.16.3, involving a path containment bypass vulnerability in the host-side SFTP server component (sshfs_server). The vulnerability exists in the validate_path function which performs inadequate path validation without proper normalization of directory traversal sequences. An attacker with root privileges inside a guest VM can inject raw SFTP frames directly into the sshfs_server process via procfs, bypassing the FUSE layer. By exploiting directory traversal sequences that match the allowed mount prefix, the attacker can force the host-side root process to access files outside the designated mount boundary. This results in arbitrary file read access on the host filesystem and enables virtual machine escape attacks.
Technical details
Mitigation steps:
Affected products:
Canonical Multipass
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-49238
https://github.com/canonical/multipass/security/advisories/GHSA-rhp2-23c4-r34w
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
