๐Ÿ” CVE Alert

CVE-2026-100838

HIGH 8.1

Contrast before 1.19.1 CopyFile Policy Symlink Subversion

CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
0th

Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.19.1, the Kata agent policies generated by the Contrast CLI contained a flaw in the CopyFile verification that allowed arbitrary writes to the guest root filesystem. A malicious process on the untrusted host able to connect to the Kata agent VSOCK could issue a series of CopyFile requests to overwrite security-critical files in the guest or trick the workload into disclosing sensitive data, effectively amounting to a full guest takeover. Users unable to upgrade can apply an equivalent rego policy fix passed to 'contrast generate --policy'.

CWE CWE-59
Vendor edgelesssys
Product contrast
Published Sep 27, 2026
Stay Ahead of the Next One

Get instant alerts for edgelesssys contrast

Be the first to know when new high vulnerabilities affecting edgelesssys contrast are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

edgelesssys / contrast
0 < 1.19.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/edgelesssys/contrast/security/advisories/GHSA-rh99-wc69-c255 vulncheck.com: https://www.vulncheck.com/advisories/contrast-before-1.19.1-copyfile-policy-symlink-subversion