PT-2026-46880 · Unknown · Singularity+1

CVE-2026-47215

·

Published

2026-06-04

·

Updated

2026-07-30

CVSS v3.1

4.8

Medium

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions SingularityCE versions prior to 4.4.2 SingularityPRO versions prior to 4.3.9 SingularityPRO versions prior to 4.1.14
Description Incorrect path string matching occurs within the limit container paths directive in singularity.conf, which is designed to restrict the paths from which containers can be executed under setuid mode. This flaw allows sibling directories with similar names to be incorrectly permitted. For instance, a configuration intended to limit paths to /data/safe would also allow containers located in /data/safe-but-unsafe to run.
Recommendations Update SingularityCE to version 4.4.2. Update SingularityPRO to version 4.3.9. Update SingularityPRO to version 4.1.14.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-47215
GHSA-WQCR-7RF3-F64M
GO-2026-5715
OPENSUSE-SU-2026:21483-1

Affected Products

Singularity
Singularitypro