CyberICT

CVE-2026-39822

Microsoft · Published July 15, 2026

CVSS v3.1

HIGH
Patch availableGet patch

Description

Root escape via symlink plus trailing slash in os. Root escape via symlink plus trailing slash in os

Affected Products

  • azl3 golang 1.25.11-3 on Azure Linux 3.0
  • azl3 golang 1.26.4-3 on Azure Linux 3.0

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H