CVE-2026-87114
Received Received - Intake

Arbitrary Code Execution in kube-compare via Untrusted Container Image

Vulnerability report for CVE-2026-87114, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: redhat-SADP

Description

A flaw was found in kube-compare. When processing a 'container://' reference path, the tool incorrectly executes an untrusted container image's entrypoint instead of merely extracting data from a stopped container. This allows a remote attacker to achieve arbitrary code execution on the operator's workstation. If the Docker daemon requires elevated privileges, the untrusted code may execute with root-mediated daemon privileges, posing a significant security risk.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
redhat kube-compare *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-829 The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability exists in the kube-compare tool. When processing a 'container://' reference path, it incorrectly runs an untrusted container image's entrypoint instead of extracting data from a stopped container. This allows a remote attacker to execute arbitrary code on the operator's workstation. If Docker requires elevated privileges, the untrusted code may run with root permissions, creating a significant security risk.

Detection Guidance

Check if kube-compare is installed and inspect container:// references in your configurations. Look for unexpected container executions or network connections from kube-compare processes. Commands like 'ps aux | grep kube-compare' or 'docker ps -a' may help identify suspicious activity.

Impact Analysis

An attacker could exploit this to run malicious code on your workstation. If Docker requires sudo, the attacker could gain root access, allowing them to install malware, steal data, or take control of your system. Even without root, they could perform actions like deleting files or exfiltrating sensitive information.

Compliance Impact

This vulnerability could lead to unauthorized code execution, potentially exposing sensitive data. This may violate GDPR's data protection requirements or HIPAA's safeguards for protected health information, depending on the data involved. Organizations using kube-compare with untrusted containers risk non-compliance and potential regulatory penalties.

Mitigation Strategies

Stop using untrusted container images with kube-compare. Ensure Docker or Podman requires authentication and restricts privileged access. Review sudo policies to limit Docker command execution to trusted users. Avoid using the container:// scheme with untrusted sources until a patch is available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87114. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart