OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-100839

HIGH · CVSS 8.4 EPSS 0.15% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-27 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The vulnerability affects the ACPI/AML handling in Contrast's confidential-computing runtime for Kubernetes, specifically in versions prior to 1.18.0, allowing an attacker with control over the host to execute arbitrary code in the guest kernel. This can lead to the disclosure or modification of sensitive guest data due to the execution of malicious AML bytecode with access to full guest memory. Organizations utilizing Linux and Kubernetes in AMD SEV-SNP environments should prioritize upgrading to version 1.18.0 or later to mitigate this high-severity risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
arbitrary code execution code execution
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-100839
Severity
HIGH
CVSS
8.4
EPSS
0.15%
Linux Kubernetes

Original NVD Description

Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.18.0, the guest kernel's ACPI/AML handling is vulnerable to an AML injection attack ("BadAML"). ACPI tables containing AML bytecode are passed from the untrusted host (QEMU) to the guest firmware (OVMF) and on to the Linux kernel, whose AML interpreter executes them. An attacker controlling the host — an assumed adversary in Contrast's threat model — can craft a table with malicious, Turing-complete AML bytecode that the guest kernel interprets with access to the full guest memory, including private pages, resulting in arbitrary code execution and disclosure or modification of confidential guest data. The issue affects the AMD SEV-SNP platforms Metal-QEMU-SNP and Metal-QEMU-SNP-GPU; Metal-QEMU-TDX is not affected because ACPI table contents are measured into RTMR 0 by OVMF on Intel TDX. Version v1.18.0 mitigates the attack by sandboxing the kernel AML interpreter so that it cannot read or write private memory pages. This weakness is not specific to Contrast but is generic to Confidential Computing setups that expose the ACPI interface to the host.