High severity8.8NVD Advisory· Published Jul 8, 2026· Updated Jul 14, 2026
CVE-2026-10037
CVE-2026-10037
Description
A sandbox escape vulnerability exists in the OpenJDK packages provided in Ubuntu. The .jar MIME handlers installed by these packages execute files marked as executable when the mailcap package is installed. A compromised or malicious sandboxed application with access to the OpenURI portal via xdg-desktop-portal-gtk can write a malicious .jar file to the host file system, set its executable bit, and trigger the handler to execute arbitrary code outside of the sandbox environment.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.