CVE-2026-39822
Microsoft · Published July 15, 2026
7.8
CVSS v3.1
HIGHPatch availableGet patch
Description
Root escape via symlink plus trailing slash in os. Root escape via symlink plus trailing slash in os
Affected Products
- azl3 golang 1.25.11-3 on Azure Linux 3.0
- azl3 golang 1.26.4-3 on Azure Linux 3.0
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H