CRI-O Sandbox State Persistence Trust-Boundary Vulnerability
A trust-boundary vulnerability in CRI-O allows an attacker to manipulate pod metadata to overwrite sandbox bookkeeping, enabling container escape via host-side resource mounting upon container recreation.
CVE search metadata
CVE search record: CVE-2026-62146. Severity: high. CVSS: 7.8. KEV: no. Product: CRI-O. Brief: CRI-O Sandbox State Persistence Trust-Boundary Vulnerability. Brief link: https://feed.craftedsignal.io/briefs/2026-09-crio-sandbox-escape/
CVE-2026-62146 describes a critical trust-boundary flaw within the CRI-O container runtime related to its sandbox state persistence mechanism. An attacker capable of influencing pod metadata can overwrite CRI-O's internally reserved sandbox bookkeeping information. This state is serialized and subsequently treated as trusted by the runtime upon a process restart or daemon reload. When the affected sandbox is triggered to recreate a container, the compromised state data directs the runtime to inadvertently mount sensitive host-side runtime-management resources directly into the container filesystem. This transition from untrusted pod input to trusted runtime configuration facilitates a container escape, granting the attacker access to host-level resources and providing a pathway for privilege escalation. This vulnerability poses a significant risk in multi-tenant environments where pod metadata may be partially accessible or influenced by non-privileged users.
Impact
Successful exploitation of CVE-2026-62146 allows an attacker to break out of the container isolation boundary. By accessing host-side runtime management resources, an attacker can achieve full host compromise, potentially leading to unauthorized data access, lateral movement within the cluster, and persistent control over the underlying node. This vulnerability affects all environments running vulnerable versions of CRI-O.
Recommendation
- Update the CRI-O runtime to the latest patched version once released by the vendor to address the sandbox state persistence flaw.
- Audit Kubernetes pod specifications to ensure that metadata fields are restricted and cannot be manipulated by untrusted users or processes.
- Monitor node-level logs for unusual container lifecycle events, such as repeated unexpected container recreations or initialization patterns associated with unauthorized configuration changes.
Immediate actions
Monitor vendor channels for the release of the patched CRI-O version addressing CVE-2026-62146.
Mitigations
Upgrade CRI-O runtime as soon as the patch is released.
CVE-2026-62146