OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-100833

HIGH · CVSS 8.2 EPSS 0.23% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-27 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

Kubernetes deployments using Contrast versions 1.14.0 through 1.23.1 are vulnerable due to a flaw in runtime policy generation that allows unauthorized container image substitutions without proper image digest verification. This vulnerability can be exploited by an attacker with access to the Kata agent API, potentially allowing them to replace a container image with a malicious payload, thereby compromising the integrity of confidential containers. Organizations utilizing these versions of Contrast should prioritize remediation to protect against potential exploitation by insiders or compromised administrators.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-100833
Severity
HIGH
CVSS
8.2
EPSS
0.23%
Kubernetes

Original NVD Description

Contrast (edgelesssys/contrast) versions 1.14.0 before 1.23.1 generate runtime policies that fail to detect all container image substitutions. A bad rebase during a Kata Containers update accidentally introduced an `allow_storage` rule that accepts storage entries using the `image_guest_pull` driver without verifying the image digest. An attacker with access to the Kata agent API — for example, a Kubernetes cluster administrator in Contrast's threat model — can therefore substitute a container image with an exploit payload, provided the substituted image satisfies the remaining policy rules, undermining the confidential container's integrity guarantees.