Critical Minetest Vulnerability Allows Remote Code Execution

Critical Minetest Vulnerability Allows Remote Code Execution

First seen 7 Sep 2026, 13:06 UTC UbuntuLinuxsecurity 57.9

Article Content

Browse articles
ThreatCluster

A significant vulnerability has been identified in Minetest, a free and open-source sandbox game, allowing attackers to execute arbitrary code on affected servers. The flaw arises from improper sanitization of the Lua sandbox environment when using LuaJIT, enabling malicious mods to escape the sandbox and gain full file system access. This vulnerability affects Ubuntu 24.04 LTS, 22.04 LTS, and 20.04 LTS versions of the minetest-server package. Users are advised to update their systems to the latest package versions to mitigate the risk. The vulnerability is tracked as CVE-2026-8732. A standard system update will apply the necessary patches. The issue was disclosed on September 7, 2026, and is critical due to the potential for exploitation by authenticated users.

Key Points: • Minetest vulnerability allows remote code execution via specially crafted network traffic. • Affected systems include Ubuntu 24.04, 22.04, and 20.04 LTS with specific minetest-server versions. • Users should update their systems immediately to mitigate the risk of exploitation.

Ask AI about this cluster

Timeline

2026-09-07
CVE-2026-8732 disclosed
A vulnerability in Minetest was disclosed, allowing remote code execution through LuaJIT sandbox escape.
Linuxsecurity
2026-09-07
Patch released
Ubuntu released updates for affected minetest-server packages to address the vulnerability.
Ubuntu