PT-2026-69150 · Unknown · Kata Containers
CVE-2026-50540
·
Published
2026-08-07
·
Updated
2026-08-24
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Kata Containers versions prior to 4.0.0
Description
The
kata-runtime allows host code execution due to an unvalidated configuration path annotation. The runtime accepts an arbitrary io.katacontainers.config path pod annotation and loads the referenced host TOML file without restriction. A pod user capable of placing a file at a host-visible path can provide a configuration that selects an attacker-controlled hypervisor or virtio-fs daemon binary, resulting in code execution as root on the host.Recommendations
Update to version 4.0.0.
Exploit
Fix
Path traversal
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kata Containers