๐Ÿ” CVE Alert

CVE-2026-77176

HIGH 8.1

Kata-containers: insufficient validation of createcontainer mount and storage rules in genpolicy

CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
0th

A flaw was found in Kata Containers. In configurations utilizing genpolicy for Confidential Containers guest protection, a malicious host operator can exploit insufficient validation of CreateContainer mount and storage rules. This allows them to mount arbitrary container-rootfs paths over sensitive host locations or provision arbitrary content, potentially exposing confidential information or enabling the acceptance of attacker-controlled input.

CWE CWE-73
Vendor red hat
Product red hat openshift container platform 4
Published Aug 20, 2026
Stay Ahead of the Next One

Get instant alerts for red hat red hat openshift container platform 4

Be the first to know when new high vulnerabilities affecting red hat red hat openshift container platform 4 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

Red Hat / Red Hat OpenShift Container Platform 4
All versions affected
Red Hat / Red Hat OpenShift Container Platform 4
All versions affected

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
access.redhat.com: https://access.redhat.com/security/cve/CVE-2026-77176 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2517502 github.com: https://github.com/kata-containers/kata-containers/security/advisories/GHSA-fmg6-v47x-52wr

Credits

Red Hat would like to thank Adam Korcz (ADA Logistics) for reporting this issue.