Sceawere

Vulnerability Detail

CVE-2026-100833UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Contrast Runtime Policy Bypass

Vulnerability Metadata

Severity
High
Score / CVSS
8.2
Creation Date
1d ago
Vendor
edgelesssys
Product
contrast
Attack Type
Improper Input Validation
Vector String
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
Attack Complexity
HIGH

Narrative and Response

Description

Contrast (edgelesssys/contrast) versions 1.14.0 before 1.23.1 generate runtime policies that fail to detect all container image substitutions. A bad rebase during a Kata Containers update accidentally introduced an `allow_storage` rule that accepts storage entries using the `image_guest_pull` driver without verifying the image digest. An attacker with access to the Kata agent API — for example, a Kubernetes cluster administrator in Contrast's threat model — can therefore substitute a container image with an exploit payload, provided the substituted image satisfies the remaining policy rules, undermining the confidential container's integrity guarantees.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.2",
  "pubDate": "2026-09-27T02:17:21.323Z",
  "pubdate": "2026-09-27T02:17:21.323Z",
  "executiveSummary": "Contrast versions 1.14.0 through 1.23.0 are susceptible to an improper authorization vulnerability concerning container image validation. The flaw arises from an incorrectly configured runtime policy that permits the usage of the image_guest_pull driver without enforcing mandatory image digest verification.\nThis vulnerability compromises the integrity guarantees inherent to confidential containers. By bypassing digest validation, an attacker capable of interacting with the Kata agent API can perform image substitution attacks, replacing authorized container images with malicious payloads. This bypass effectively undermines the hardware-backed security boundaries established by confidential computing environments.\nThe risk is significant for Kubernetes environments where the threat model includes cluster administrators who possess access to the Kata agent API. Successful exploitation allows for the execution of arbitrary code within the guest environment by bypassing the image attestation mechanisms intended to prevent unauthorized software execution.\nThe vulnerability is a direct result of a flawed rebase during a Kata Containers update, which introduced an overly permissive allow_storage rule. Remediation requires updating Contrast to version 1.23.1 or later to restore rigorous image authentication protocols.",
  "technicalDetails": "The vulnerability originates within the runtime policy generation logic of Contrast versions 1.14.0 to 1.23.0. During a Kata Containers rebase, an inadvertent modification introduced an overly permissive rule within the policy configuration: specifically, an 'allow_storage' rule that incorrectly authorizes the 'image_guest_pull' driver.\nUnder standard operating conditions for confidential containers, the Kata agent must strictly enforce image integrity by verifying the digest of the container image before initialization. This ensures that the code executing inside the guest environment matches the cryptographically signed and authorized image defined in the deployment policy.\nThe flaw allows the 'image_guest_pull' driver to bypass this essential cryptographic verification process. Because the policy fails to mandate a digest check for storage entries utilizing this driver, the guest agent accepts any image presented by the attacker, provided it conforms to superficial policy requirements.\nThe attack flow proceeds as follows: 1) The attacker gains or leverages existing access to the Kata agent API, a capability explicitly included in Contrast's threat model for cluster administrators. 2) The attacker initiates a container deployment or modification request that utilizes the compromised 'image_guest_pull' storage path. 3) By substituting the legitimate, trusted container image with a malicious exploit payload, the attacker bypasses the host-level integrity checks that would typically block unauthorized images. 4) The Kata agent, relying on the flawed runtime policy, pulls and executes the unauthorized image within the confidential guest container environment.\nPost-exploitation, the attacker achieves arbitrary code execution within the isolated guest environment. This subverts the confidential container's security objectives, allowing for the potential exfiltration of sensitive workloads, manipulation of data processed within the enclave, or lateral movement if the containerized application has been compromised. The exposure is local to the node where the agent API is accessible, typically requiring privileged access to the Kubernetes cluster control plane or node infrastructure to influence the agent's configuration or orchestration tasks."
}
CVE-2026-100833: Contrast Runtime Policy Bypass (HIGH Severity, CVSS: 8.2) | Sceawere