CVE-2026-87766
HighAdvisory
Published 10 Sept 2026In the index since 11 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 8.8
- base score, highest
- EPSS
- 0.001
- 4th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 6
- of 17,781 indexed, latest versions
- Container images
- 6
- deployed by those charts
- Fix available
- None
- affected package
The matching OSV records carry no description.
Carried by container images the latest versions of 6 of 17,781 indexed charts deploy, on 6 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| bubblewrapdeb | 0.4.0-1ubuntu4.1, 0.6.1-1, 0.6.1-1ubuntu0.1, 0.11.1-1ubuntu0.1 | no fix listed | 6 |
- OSV records
- UBUNTU-CVE-2026-87766
Charts affected
6 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| penpotpenpotOfficialVerified publisher | 1.9.0 | 1 of 4See more | 4,314 |
| photoprismandrenarchyVerified publisher | 8.15.0 | 1 of 1See more | 8,825 |
| business-api-ecosystemfiware | 1.1.0 | 1 of 4See more | 64,489 |
| ingresslivekit-server | 1.2.2 | 1 of 1See more | 10,716 |
| vrisingryuunosukeds3 | 0.1.0 | 1 of 1See more | 7,295 |
| photoprismschoolguys-helmcharts | 0.3.8 | 1 of 1See more | 10,348 |
Container images carrying it
6 by charts deploying them
A fixed version is listed for 0 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| fiware/ | 29456835bb2c | bubblewrap | no fix listed | 1 |
| livekit/ | 1ab01641b366 | bubblewrap | no fix listed | 1 |
| penpotapp/ | 72a8061e8806 | bubblewrap | no fix listed | 1 |
| photoprism/ | 650c6ad5a651 | bubblewrap | no fix listed | 1 |
| photoprism/ | 958642220223 | bubblewrap | no fix listed | 1 |
| trueosiris/ | 9356f98ad561 | bubblewrap | no fix listed | 1 |