VDB
CVE-2026-10037
CVE-2026-10037
PUBLISHED
CVSS 8.8 HIGH
Reported by canonical · Published July 8, 2026
A sandbox escape vulnerability exists in the OpenJDK packages provided in Ubuntu. The .jar MIME handlers installed by these packages execute files marked as executable when the mailcap package is installed. A compromised or malicious sandboxed application with access to the OpenURI portal via xdg-desktop-portal-gtk can write a malicious .jar file to the host file system, set its executable bit, and trigger the handler to execute arbitrary code outside of the sandbox environment.
Risk Scores
CVSS 3.1
8.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Canonical | Ubuntu | |
| Canonical | Ubuntu | |
| Canonical | Ubuntu | |
| Canonical | Ubuntu | |
| Canonical | Ubuntu | |
| Canonical | Ubuntu | |
| Canonical | Ubuntu | |
| Canonical | Ubuntu | |
| Canonical | Ubuntu | |
| Canonical | Ubuntu | 0, 0, 0 |
| Canonical | Ubuntu | |
| Canonical | Ubuntu | |
| Canonical | Ubuntu | |
| Canonical | Ubuntu | |
| Canonical | Ubuntu | |
| Canonical | Ubuntu | |
| Canonical | Ubuntu | |
| Canonical | Ubuntu | |
| Canonical | Ubuntu | |
| Canonical | Ubuntu | 0, 0, 0 |
Timeline
- Jul 8, 2026 CVE Published
- Jul 9, 2026 EPSS Score
- Jul 9, 2026 Coalition ESS Score
- Jul 10, 2026 Security Advisory
- Jul 14, 2026 CVE Updated
- Aug 24, 2026 EPSS Score
- Sep 6, 2026 EPSS Score
- Sep 16, 2026 EPSS Score