Description
Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to perform tampering locally.
Published: 2026-08-11
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper link resolution before file access in the Windows Container Isolation FS Filter Driver, unionfs.sys, enables an attacker with local authorization to alter files. This flaw can be exploited to modify or replace files that the container isolation mechanism protects, potentially compromising container integrity or persistence of malicious code.

Affected Systems

Microsoft Windows 11 version 26H1 is affected. Containers running on this OS that rely on the unionfs.sys filter driver are vulnerable if the OS is at this release level.

Risk and Exploitability

The CVSS score of 5.5 indicates a moderate risk. The EPSS score of less than 1% suggests a low likelihood of exploitation at present, and the vulnerability is not listed in CISA's KEV catalog. Exploitation requires local, authorized access to the system, meaning the threat level is limited to environments where privileged users or compromised local software can leverage the flaw to tamper with container files.

Generated by OpenCVE AI on August 12, 2026 at 19:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Windows updates that include the fix for the unionfs.sys vulnerability.
  • Limit local administrative privileges and enforce least‑privilege access for container workloads.
  • Continuously monitor the filesystem for unexpected changes, especially within container isolation paths to detect potential tampering attempts.

Generated by OpenCVE AI on August 12, 2026 at 19:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:*

Fri, 14 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows 11 26h1
Vendors & Products Microsoft windows 11 26h1

Tue, 11 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to perform tampering locally.
Title Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering Vulnerability
First Time appeared Microsoft
Microsoft windows 11 26h1
Weaknesses CWE-59
CPEs cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft
Microsoft windows 11 26h1
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 26h1 Windows 11 26h1
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-31T20:06:22.952Z

Reserved: 2026-08-10T18:36:42.030Z

Link: CVE-2026-72971

cve-icon Vulnrichment

Updated: 2026-08-11T19:20:26.510Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:19:15.220

Modified: 2026-08-14T18:21:30.457

Link: CVE-2026-72971

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T12:45:16Z

Weaknesses
  • CWE-59

    Improper Link Resolution Before File Access ('Link Following')