Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 12 Aug 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 07 Aug 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Kata Containers, affecting both its Rust and Go runtimes. An authenticated pod user can exploit this by setting the `io.katacontainers.config_path` annotation to an arbitrary configuration file on the host. This allows the attacker to control privileged runtime settings, leading to the execution of malicious binaries as root on the host system. The primary consequence is arbitrary code execution with elevated privileges. | Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Prior to version 4.0.0, kata-runtime is vulnerable to host code execution via an unvalidated configuration path annotation. The runtime accepts an arbitrary io.katacontainers.config_path pod annotation and loads the referenced host TOML file without restriction. As a result, a pod user who can place a file at a host-visible path can supply a configuration that selects an attacker-controlled hypervisor or virtio-fs daemon binary, executing code as root on the host. This issue is fixed in version 4.0.0. |
| Title | kata-runtime: kata-runtime-rs: Kata Containers: Arbitrary code execution via manipulated configuration path | Kata Containers: Config Path Annotation Arbitrary File Loading |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Thu, 23 Jul 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Katacontainers
Katacontainers kata-containers |
|
| Vendors & Products |
Katacontainers
Katacontainers kata-containers |
Thu, 23 Jul 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Kata Containers, affecting both its Rust and Go runtimes. An authenticated pod user can exploit this by setting the `io.katacontainers.config_path` annotation to an arbitrary configuration file on the host. This allows the attacker to control privileged runtime settings, leading to the execution of malicious binaries as root on the host system. The primary consequence is arbitrary code execution with elevated privileges. | |
| Title | kata-runtime: kata-runtime-rs: Kata Containers: Arbitrary code execution via manipulated configuration path | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-12T22:15:26.669Z
Reserved: 2026-06-04T20:37:18.653Z
Link: CVE-2026-50540
Updated: 2026-08-12T22:09:42.119Z
Status : Received
Published: 2026-08-07T21:17:28.827
Modified: 2026-08-12T23:17:21.560
Link: CVE-2026-50540
OpenCVE Enrichment
Updated: 2026-08-07T23:30:17Z