CVE-2026-10037

A sandbox escape vulnerability exists in the OpenJDK packages provided in Ubuntu. The .jar MIME handlers installed by these packages execute files marked as executable when the mailcap package is installed. A compromised or malicious sandboxed application with access to the OpenURI portal via xdg-desktop-portal-gtk can write a malicious .jar file to the host file system, set its executable bit, and trigger the handler to execute arbitrary code outside of the sandbox environment.
Configurations

No configuration.

History

No history.

Information

Published : 2026-07-08 22:17

Updated : 2026-07-14 15:16


NVD link : CVE-2026-10037

Mitre link : CVE-2026-10037

CVE.ORG link : CVE-2026-10037


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation