PT-2026-69150 · Unknown · Kata Containers

CVE-2026-50540

·

Published

2026-08-07

·

Updated

2026-08-24

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Kata Containers versions prior to 4.0.0
Description The kata-runtime allows host code execution due to an unvalidated configuration path annotation. The runtime accepts an arbitrary io.katacontainers.config path pod annotation and loads the referenced host TOML file without restriction. A pod user capable of placing a file at a host-visible path can provide a configuration that selects an attacker-controlled hypervisor or virtio-fs daemon binary, resulting in code execution as root on the host.
Recommendations Update to version 4.0.0.

Exploit

Fix

Path traversal

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-94610
AZL-94622
AZL-94679
AZL-94682
CVE-2026-50540
GHSA-MP2J-XM59-QFGW
OESA-2026-3405

Affected Products

Kata Containers