CVE-2026-49238

8.4

Canonical · Multipass

A path traversal vulnerability in Canonical Multipass allows local attackers to access restricted directories.

Executive summary

A path traversal vulnerability in Canonical Multipass before version 1.16.3 could allow local attackers to bypass file system restrictions.

Vulnerability

This is a Path Traversal (CWE-22) vulnerability requiring local, low-privileged access to the host. An attacker can manipulate pathnames to escape intended directory constraints, potentially leading to unauthorized data access.

Business impact

While the attack requires local access, the potential for unauthorized access to sensitive files or configuration data is significant. The CVSS score of 8.4 reflects the risk of local privilege escalation or sensitive information disclosure, which could compromise the integrity of the host environment.

Remediation

Immediate Action: Update Canonical Multipass to version 1.16.3 or later to remediate the path traversal flaw.

Proactive Monitoring: Review local system logs for unusual file access activities initiated by low-privileged user accounts.

Compensating Controls: Implement strict file system permissions and ensure that only authorized users have access to the host machine running the Multipass software.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Administrators should immediately verify their Multipass installation versions and upgrade to 1.16.3. Due to the potential for local privilege escalation, prompt patching is essential for maintaining host security.

More Canonical CVEs