HIGHVulnerability
CVE-2026-77176
A flaw was found in Kata Containers. In configurations utilizing genpolicy for Confidential Containers guest protection, a malicious host operator can exploit insufficient validation of CreateContainer mount and storage rules. This allows them to mount arbitrary container-rootfs paths over sensitive host locations or provision arbitrary content, potentially exposing confidential information or enabling the acceptance of attacker-controlled input.
Properties
- severity
- HIGH
- score
- 8.1
- epss_score
- 0.00411
- cve_id
- CVE-2026-77176
- vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- published_at
- 2026-08-20T17:19:49.773
- last_modified
- 2026-09-01T12:17:47.290
- epss_percentile
- 0.34287
Related Entities (3)
ENRICHED_BY (1)
→[Source]FIRST EPSS
HAS_WEAKNESS (1)
→[Weakness]External Control of File Name or Path
DESCRIBED_BY (1)
→[Source]NVD
Explore deeper with Ninja Signal's threat intelligence graph