CVE detail
CVE-2025-57847
A container privilege escalation flaw was found in certain Ansible Automation Platform images. This issue arises from the /etc/passwd file being created with group-writable permissions during the build process. In certain conditions, an attacker who can execute commands within an affected container, even as a non-root user, can leverage their membership in the root group to modify the /etc/passwd file. This vulnerability allows an attacker to add a new user with any arbitrary UID, including UID 0, gaining full root privileges within the container.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 16.1 · diversity 6.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
4 source links · newest first
- https://bugzilla.redhat.com/show_bug.cgi?id=2391092bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comApr 8, 2026, 2:16 PM - https://access.redhat.com/security/cve/CVE-2025-57847access.redhat.com
No excerpt available.
Exploitaccess.redhat.comApr 8, 2026, 2:16 PM - https://access.redhat.com/errata/RHSA-2026:42144access.redhat.com
No excerpt available.
Exploitaccess.redhat.comApr 8, 2026, 2:16 PM - https://access.redhat.com/errata/RHSA-2026:42141access.redhat.com
No excerpt available.
Exploitaccess.redhat.comApr 8, 2026, 2:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-19893CVSS 2.3 · Low
A vulnerability was identified in D-Link DIR-842 2.01.B04. This impacts an unknown function of the file /etc/vsftpd.conf of the component vsftpd. Such manipulation leads to incorr…
- CVE-2026-19841CVSS 2.3 · Low
A flaw has been found in TRENDNET TEW-813DRU 1.01b01. Impacted is an unknown function of the file /etc/vsftpd.conf of the component vsftpd. This manipulation causes incorrect defa…
- CVE-2026-63425CVSS 8.5 · High
During an internal security assessment, a potential improper permissions vulnerability was discovered in Lenovo Dock Manager that could allow a local authenticated user to execute…
- CVE-2025-52640CVSS 4.7 · Medium
HCL AION is affected by a vulnerability where the shared storage used by product components is architected without sufficient access separation. Processes sharing the storage may…
- CVE-2026-65940CVSS 6.8 · Medium
In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can write arbitrary files to a web-accessible location on the host server.
- CVE-2026-48790CVSS 5.5 · Medium
Turso CLI is the command line interface (CLI) to the open-source database Turso. Versions prior to 1.0.26 persist the user's Turso platform JWT to `settings.json` using Viper's de…