# CVE-2026-15809

## Summary

- **CVE ID:** CVE-2026-15809
- **Severity:** HIGH
- **CVSS Score:** 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-134
- **Published:** Jul 15, 2026
- **Last Modified:** Sep 2, 2026

## Description

A flaw was found in CRI-O. The fix for a previous vulnerability (CVE-2022-4318) was incorrect, allowing it to be bypassed. An attacker capable of setting environment variables on a container can inject a newline character into the HOME environment variable. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable.

## Affected Products

- Red Hat — Red Hat OpenShift Container Platform 4.22 (0:1.35.6-5.rhaos4.22.git41f610b.el9)
- Red Hat — Red Hat OpenShift Container Platform 4.20 (0:1.33.13-5.rhaos4.20.git7ebc848.el9)
- Red Hat — Red Hat OpenShift Container Platform 4.21 (0:1.34.11-4.rhaos4.21.git358c4b4.el9)
- Red Hat — Red Hat OpenShift Container Platform 4.19 (0:1.32.13-11.rhaos4.19.git089e95c.el9)

## References

- [CNA](https://access.redhat.com/security/cve/CVE-2026-15809)
- [CNA](https://access.redhat.com/security/cve/cve-2022-4318)
- [CNA](https://bugzilla.redhat.com/show_bug.cgi?id=2500846)
- [CNA](https://github.com/cri-o/cri-o/pull/6450)
- [CNA](https://github.com/cri-o/cri-o/pull/6524)
- [CNA](https://access.redhat.com/errata/RHSA-2026:57361)
- [CNA](https://access.redhat.com/errata/RHSA-2026:60444)
- [CNA](https://access.redhat.com/errata/RHSA-2026:60449)
- [CNA](https://access.redhat.com/errata/RHSA-2026:60452)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.16%
- **EPSS Percentile:** 6.0

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._