Junglewise Threat Intelligence

CVE-2026-1386: AWS Firecracker arbitrary host file overwrite in jailer via symlink

CVE-2026-1386 · Severity: high · Published 2026-01-23

Technologies: Amazon AWS. Vendors: AWS, Amazon Web Services, Amazon.

Executive brief

Firecracker is a virtualization tool used to run secure, isolated containers and serverless functions. A vulnerability in its 'jailer' component—which is designed to provide an extra layer of security—could allow a user to bypass these protections and overwrite critical files on the underlying host server. This could lead to a complete compromise of the host system, though AWS-managed services are not affected due to existing security configurations.

Technical details

A vulnerability exists in the Firecracker jailer component where improper handling of symbolic links can lead to an arbitrary file overwrite on the host filesystem. The jailer is intended to provide a chroot-based isolation layer for microVMs; however, if an attacker can manipulate files within the jailer's directory structure, they can use symlinks to target files outside the intended sandbox. Exploitation requires the ability to create symlinks within the jailer folder, which is typically possible if directory permissions are not strictly managed. The issue is resolved in versions v1.14.1 and v1.13.2. As a workaround, administrators should restrict the jailer folder to trusted users using strict UNIX permissions (e.g., chmod 700).

Affected products

  • AWS Firecracker v1.13.1 and earlier, 1.14.0

Timeline

  • 2026-01-23: disclosed
  • 2026-01-23: advisory
  • 2026-01-23: patched: Fixed in v1.14.1 and v1.13.2

References

Related threats