Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4358 articles · 196331 vulns · 36/41 feeds (7d)
← Back to list
9.6
CVE-2026-50540
kata-containers · kata-containers

Kata Containers: Config Path Annotation Arbitrary File Loading

Description

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Prior to version 4.0.0, kata-runtime is vulnerable to host code execution via an unvalidated configuration path annotation. The runtime accepts an arbitrary io.katacontainers.config_path pod annotation and loads the referenced host TOML file without restriction. As a result, a pod user who can place a file at a host-visible path can supply a configuration that selects an attacker-controlled hypervisor or virtio-fs daemon binary, executing code as root on the host. This issue is fixed in version 4.0.0.

Affected Products

VendorProductVersions
kata-containerskata-containers< 4.0.0

References

  • https://github.com/kata-containers/kata-containers/security/advisories/GHSA-mp2j-xm59-qfgw(x_refsource_CONFIRM)
  • https://github.com/kata-containers/kata-containers/commit/03cc670076099530f4e1e9cb22849afdafb20f65(x_refsource_MISC)

Related News (3 articles)

Tier C
oss-security11h ago
Vulnerability in Kata Containers runtimes (both rust and go) (CVE-2026-50540)
→ No new info (linked only)
Tier A
Microsoft MSRC14d ago
CVE-2026-50540 Kata Containers: Config Path Annotation Arbitrary File Loading
→ No new info (linked only)
Tier C
VulDB28d ago
CVE-2026-50540 | kata-containers Kata Containers Configuration Path privilege escalation
→ No new info (linked only)
CVSS 3.19.6 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
CISA KEV❌ No
Actively exploited❌ No
CWECWE-20, CWE-22
PublishedAug 7, 2026
Trending Score48
Source articles3
Independent3
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (3)

NONECVE-2026-47243
Kata guest escape: runtime-rs guest-root to host-root escape via virtiofs
Trending: 10
MEDIUMCVE-2026-64676
Kata Containers: Unauthorized mem-agent ttRPC methods let an untrusted host tamper with confidential-guest memory
Trending: 6
MEDIUMCVE-2026-44210
Kata Containers have VM Escape via virtiofsd Argument Injection through Default-Enabled Pod Annotations
Trending: 2

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 7, 2026
Discovered by ZDM
Aug 7, 2026