VDB

CVE-2026-10037

CVE-2026-10037 PUBLISHED CVSS 8.8 HIGH

Reported by canonical · Published July 8, 2026

A sandbox escape vulnerability exists in the OpenJDK packages provided in Ubuntu. The .jar MIME handlers installed by these packages execute files marked as executable when the mailcap package is installed. A compromised or malicious sandboxed application with access to the OpenURI portal via xdg-desktop-portal-gtk can write a malicious .jar file to the host file system, set its executable bit, and trigger the handler to execute arbitrary code outside of the sandbox environment.

Risk Scores

CVSS 3.1
8.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersions
CanonicalUbuntu
CanonicalUbuntu
CanonicalUbuntu
CanonicalUbuntu
CanonicalUbuntu
CanonicalUbuntu
CanonicalUbuntu
CanonicalUbuntu
CanonicalUbuntu
CanonicalUbuntu0, 0, 0
CanonicalUbuntu
CanonicalUbuntu
CanonicalUbuntu
CanonicalUbuntu
CanonicalUbuntu
CanonicalUbuntu
CanonicalUbuntu
CanonicalUbuntu
CanonicalUbuntu
CanonicalUbuntu0, 0, 0

Timeline

  • Jul 8, 2026 CVE Published
  • Jul 9, 2026 EPSS Score
  • Jul 9, 2026 Coalition ESS Score
  • Jul 10, 2026 Security Advisory
  • Jul 14, 2026 CVE Updated
  • Aug 24, 2026 EPSS Score
  • Sep 6, 2026 EPSS Score
  • Sep 16, 2026 EPSS Score

References

  • issue-tracking
Open in Interactive Console →
$ Console Community · 100/wk Open console ›