PT-2026-99453 · Contrast · Contrast

·

CVE-2026-100833

·

Published

2026-09-27

·

Updated

2026-09-28

CVSS v3.1

8.2

High

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Contrast versions 1.14.0 through 1.23.0
Description Runtime policies are generated that fail to detect all container image substitutions. This occurs because an allow storage rule accepts storage entries using the image guest pull driver without verifying the image digest. An attacker with access to the Kata agent API can substitute a container image with an exploit payload, provided the substituted image satisfies the remaining policy rules, which undermines the integrity guarantees of the confidential container.
Recommendations Update Contrast to version 1.23.1.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100833
GHSA-M2QG-WRXV-H898

Affected Products

Contrast