CVE-2026-100838 Details
Description
Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.19.1, the Kata agent policies generated by the Contrast CLI contained a flaw in the CopyFile verification that allowed arbitrary writes to the guest root filesystem. A malicious process on the untrusted host able to connect to the Kata agent VSOCK could issue a series of CopyFile requests to overwrite security-critical files in the guest or trick the workload into disclosing sensitive data, effectively amounting to a full guest takeover. Users unable to upgrade can apply an equivalent rego policy fix passed to 'contrast generate --policy'.
A vulnerability exists in Contrast versions prior to 1.19.1, specifically within the Kata agent policies generated by the Contrast CLI. The issue arises from a flaw in the CopyFile verification process, which permitted arbitrary writes to the guest root filesystem. This vulnerability could be exploited by a malicious process on the untrusted host that connects to the Kata agent VSOCK. Such a process could send a series of CopyFile requests to overwrite critical security files in the guest or manipulate the workload into revealing sensitive information, effectively leading to a complete takeover of the guest environment.
Users can upgrade to Contrast version 1.19.1, where this issue has been patched. If upgrading is not possible, an equivalent rego policy fix can be applied by passing it to 'contrast generate --policy'.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/edgelesssys/contrast/security/advisories/GHSA-rh99-wc69-c255 | [email protected] | AdvisoryRemedyVendor |
| https://www.vulncheck.com/advisories/contrast-before-1.19.1-copyfile-policy-symlink-subversion | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-59 | Improper Link Resolution Before File Access ('Link Following') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Edgelesssys Contrast | <= 1.19.0 (semver) < 1.20.0 (semver) |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 27, 2026 | New CVE Received | [email protected] |
Volerion