rootpwn

high · CVSS v3 8.2 · CVSS v4 7.6 · EPSS 0.00226

CVE-2026-100833

Contrast (edgelesssys/contrast) versions 1.14.0 before 1.23.1 generate runtime policies that fail to detect all containe…

Description

Contrast (edgelesssys/contrast) versions 1.14.0 before 1.23.1 generate runtime policies that fail to detect all container image substitutions. A bad rebase during a Kata Containers update accidentally introduced an `allow_storage` rule that accepts storage entries using the `image_guest_pull` driver without verifying the image digest. An attacker with access to the Kata agent API — for example, a Kubernetes cluster administrator in Contrast's threat model — can therefore substitute a container image with an exploit payload, provided the substituted image satisfies the remaining policy rules, undermining the confidential container's integrity guarantees.

Scores

Severity
high
CVSS v2
6.6
CVSS v3
8.2
CVSS v4
7.6
EPSS
0.00226

← All CVEs