PT-2026-32953 · Podman · Podman

·

CVE-2026-33414

·

Published

2026-04-14

·

Updated

2026-06-25

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Podman versions 4.8.0 through 5.8.1
Description A command injection issue exists in the HyperV machine backend within the file pkg/machine/hyperv/stubber.go. The VM image path is inserted into a PowerShell double-quoted string without sanitization, which allows for $() subexpression injection. Since PowerShell evaluates subexpressions inside double-quoted strings before executing the outer command, an attacker who controls the VM image path via a crafted machine name or image directory can execute arbitrary PowerShell commands. This occurs with the privileges of the Podman process, which on typical Windows installations results in SYSTEM-level code execution. This issue exclusively affects Windows.
Recommendations Update to version 5.8.2.

Exploit

Fix

OS Command Injection

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-33414
GHSA-HC8W-H2MF-HP59
GO-2026-5421
OPENSUSE-SU-2026:10706-1
RHSA-2026:8211

Affected Products

Podman