OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-87114

HIGH · CVSS 7.1 EPSS 0.20% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-28 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

A vulnerability in kube-compare allows remote attackers to execute arbitrary code on an operator's workstation by improperly handling 'container://' reference paths, leading to the execution of untrusted container images. If the Docker daemon operates with elevated privileges, this could result in the execution of malicious code with root-level access, significantly increasing the risk to the system. Organizations using Docker and kube-compare should prioritize patching this vulnerability to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
arbitrary code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-87114
Severity
HIGH
CVSS
7.1
EPSS
0.20%
Docker

Original NVD Description

A flaw was found in kube-compare. When processing a 'container://' reference path, the tool incorrectly executes an untrusted container image's entrypoint instead of merely extracting data from a stopped container. This allows a remote attacker to achieve arbitrary code execution on the operator's workstation. If the Docker daemon requires elevated privileges, the untrusted code may execute with root-mediated daemon privileges, posing a significant security risk.