DIRAS TAKE
Urgent—public exploit code exists for this runAsNonRoot bypass, so treat exposed containerd hosts and image registries as high priority for mitigation and containment.
What is CVE-2026-46680?
An attacker who can provide or run a specially crafted container image can cause a container managed by containerd to start with UID 0 despite runAsNonRoot controls. CVE-2026-46680 affects containerd versions < 1.7.32, >= 2.0.4 and < 2.0.9, >= 2.0.10 and < 2.2.4, and >= 2.2.5 and < 2.3.1. The bug arises when an unusually large numeric entry in the image’s user field is misinterpreted and, if the image supplies a corresponding /etc/passwd entry mapping that value to root, the container ends up running as root. An attacker needs the ability to supply or run the image; the CVSS vector indicates local access and user interaction are required. The weakness is classified as CWE-269 (Improper Privilege Management).
Vector CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Which versions of containerd containerd are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| containerd | < 1.7.32 | |
| containerd | >= 2.0.4, < 2.0.9 | |
| containerd | >= 2.0.10, < 2.2.4 | |
| containerd | >= 2.2.5, < 2.3.1 |
Is CVE-2026-46680 being exploited?
Public exploit code is available.
How to fix CVE-2026-46680
- Restrict which images can be run: enforce image provenance, require signed images, and block untrusted images at the registry or admission-controller level.
- Harden image supply: scan images for unexpected /etc/passwd contents and disallow images that override user mappings.
- Apply policy enforcement in the orchestrator (admission controllers) to validate user/UID semantics before containers are admitted.
- Monitor containerd and orchestration logs for unexpected UID 0 executions and suspicious image pull/run events and follow vendor guidance when posted.
Frequently asked questions
Is CVE-2026-46680 being actively exploited?
Public exploit code is available for CVE-2026-46680.
Which containerd versions are affected by CVE-2026-46680?
Affected ranges include containerd < 1.7.32; versions >= 2.0.4 and < 2.0.9; >= 2.0.10 and < 2.2.4; and >= 2.2.5 and < 2.3.1 as reported in the advisory data.
Is there a patch for CVE-2026-46680?
As of 2026-09-29 there is no patch listed in the provided facts.
Does CVE-2026-46680 require authentication?
Per the provided CVSS vector, the issue requires local access and user interaction (AV:L and UI:R) and does not require prior privileges (PR:N).
References
- nvd.nist.gov/vuln/detail/CVE-2026-46680
- cve.org/CVERecord?id=CVE-2026-46680
- github.com/containerd/containerd/security/advisories/GHSA-fqw6-gf59-qr4w
- All containerd CVEs on CVE Radar
- CVEs published in September 2026