OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2025-71426

HIGH · CVSS 7.1 EPSS 0.14% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-27 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

Kubernetes deployments using Contrast versions prior to 1.4.1 are vulnerable due to a flaw in the Coordinator recovery process, which fails to validate the seed from the recovering party. This allows an attacker to deploy a rogue Coordinator that can impersonate legitimate workload owners and issue certificates that compromise workload secrets. Organizations utilizing Contrast in their Kubernetes environments should prioritize this vulnerability to prevent potential data breaches and unauthorized access to sensitive information.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2025-71426
Severity
HIGH
CVSS
7.1
EPSS
0.14%
Kubernetes

Original NVD Description

Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.4.1, a recovering Coordinator does not verify the seed supplied by the recovering party. An attacker can therefore stand up a rogue Coordinator whose manifest passes validation but whose secret seed is attacker-controlled. If network traffic is redirected from the legitimate Coordinator to the attacker's Coordinator, a workload owner can be impersonated when they either set a new manifest without comparing the returned root CA certificate against the existing one (the default behavior of the contrast CLI) or verify the Coordinator without comparing the root CA certificate against a trusted reference. Under these conditions the attacker can issue certificates that chain back to the rogue Coordinator's root CA and recover arbitrary workload secrets of workloads deployed after the attack. Secrets of the legitimate Coordinator (seed, workload secrets, CA), workload integrity, and certificates chaining to the mesh CA are not affected.