CVE-2026-77176
Received Received - Intake

Kata Containers Confidential Containers Guest Protection Bypass

Vulnerability report for CVE-2026-77176, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-20

Last updated on: 2026-08-20

Assigner: redhat-SADP

Description

A flaw was found in Kata Containers. In configurations utilizing genpolicy for Confidential Containers guest protection, a malicious host operator can exploit insufficient validation of CreateContainer mount and storage rules. This allows them to mount arbitrary container-rootfs paths over sensitive host locations or provision arbitrary content, potentially exposing confidential information or enabling the acceptance of attacker-controlled input.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-20
Last Modified
2026-08-20
Generated
2026-08-20
AI Q&A
2026-08-20
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
kata_containers kata_containers *
kata_containers kata_containers 4.1.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-73 The product allows user input to control or influence paths or file names that are used in filesystem operations.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-77176 is a flaw in Kata Containers where a malicious host operator can exploit insufficient validation of mount and storage rules in genpolicy for Confidential Containers. This allows mounting arbitrary container-rootfs paths over sensitive host locations like /etc/hostname or /etc/hosts, or provisioning arbitrary content into /dev/shm and /dev/termination-log.

Detection Guidance

Check Kata Containers version with 'kata-runtime --version' to confirm if it is below 4.1.0. Inspect container runtime logs for suspicious CreateContainer requests or mount operations targeting sensitive paths like /etc/hostname, /etc/hosts, or Kubernetes service account tokens.

Impact Analysis

This vulnerability can expose confidential information by allowing attackers to mount malicious paths over sensitive host locations. It may also enable acceptance of attacker-controlled input, potentially compromising confidentiality and integrity of data processed by the containerized application.

Compliance Impact

This vulnerability could lead to unauthorized access or modification of sensitive data stored in paths like /etc/hostname, /etc/hosts, or Kubernetes/Azure service-account tokens. Such exposure risks violating GDPR's data protection principles or HIPAA's confidentiality requirements if confidential information is compromised.

Mitigation Strategies

Upgrade Kata Containers to version 4.1.0 or later immediately. Disable genpolicy-based guest protection if not required. Review and restrict host operator permissions to prevent malicious CreateContainer requests. Monitor for unauthorized file modifications in sensitive directories.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-77176. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart