CVE-2026-33414

MEDIUM EPSS 39.6%
Published Apr 14, 20262mo ago · Modified Jun 17, 20261w ago
4.0 CVSS 4.0
Medium
Find Similar
Published Apr 14, 2026 2mo ago
Last Modified Jun 17, 2026 1w ago

Description

Podman is a tool for managing OCI containers and pods. Versions 4.8.0 through 5.8.1 contain a command injection vulnerability in the HyperV machine backend in pkg/machine/hyperv/stubber.go, where the VM image path is inserted into a PowerShell double-quoted string without sanitization, allowing $() subexpression injection. Because PowerShell evaluates subexpressions inside double-quoted strings before executing the outer command, an attacker who can control the VM image path through a crafted machine name or image directory can execute arbitrary PowerShell commands with the privileges of the Podman process. On typical Windows installations this means SYSTEM-level code execution, and only Windows is affected as the code is exclusive to the HyperV backend. This issue has been patched in version 5.8.2.

CVSS Details

Base Score
4.0
Exploitability
Impact
Vector string
CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Attack Vector Local
Attack Complexity High
Privileges Required High
User Interaction None
Scope X

Threat Intelligence

EPSS Exploit Probability
39.6% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-78 OS Command Injection Injection

Affected Products 2

VendorProductVersionRange
podman_projectpodman*≥4.8.0  –  <5.8.2
microsoftwindows*any

References 2

  • github.com https://github.com/containers/podman/commit/571c842bd357ee626019ea97d030fb772fc654ed
    Patch
  • github.com https://github.com/containers/podman/security/advisories/GHSA-hc8w-h2mf-hp59
    PatchVendor Advisory

Remediation

  • github.com https://github.com/containers/podman/commit/571c842bd357ee626019ea97d030fb772fc654ed
    Patch
  • github.com https://github.com/containers/podman/security/advisories/GHSA-hc8w-h2mf-hp59
    PatchVendor Advisory