Sceawere
Vulnerability Detail
CVE-2026-100838UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Contrast Agent Arbitrary File Write
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.1
- Creation Date
- 1d ago
- Vendor
- edgelesssys
- Product
- contrast
- Attack Type
- Improper Link Resolution Before File Access ('Link Following')
- Vector String
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.19.1, the Kata agent policies generated by the Contrast CLI contained a flaw in the CopyFile verification that allowed arbitrary writes to the guest root filesystem. A malicious process on the untrusted host able to connect to the Kata agent VSOCK could issue a series of CopyFile requests to overwrite security-critical files in the guest or trick the workload into disclosing sensitive data, effectively amounting to a full guest takeover. Users unable to upgrade can apply an equivalent rego policy fix passed to 'contrast generate --policy'.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.1",
"pubDate": "2026-09-27T02:17:22.083Z",
"pubdate": "2026-09-27T02:17:22.083Z",
"executiveSummary": "Contrast, a confidential-computing runtime for Kubernetes, is susceptible to an arbitrary file write vulnerability within its Kata agent policies.\nThis vulnerability, present in versions prior to 1.19.1, stems from improper validation logic in the CopyFile function implemented within the generated Kata agent policies.\nA malicious process residing on the untrusted host that can interface with the Kata agent via the VSOCK protocol can leverage this flaw to perform unauthorized write operations to the guest root filesystem.\nThe impact of this vulnerability is critical, as it allows for the corruption of security-critical files or the exfiltration of sensitive workload data, effectively resulting in a full compromise of the guest environment.\nThe exploitation does not require prior authentication within the guest but relies on the attacker's ability to communicate with the Kata agent via the VSOCK interface.\nUsers are strongly advised to upgrade to version 1.19.1 or later. If upgrading is not immediately feasible, applying a corrected rego policy via the 'contrast generate --policy' command is recommended to mitigate the exposure.",
"technicalDetails": "The vulnerability resides within the policy-generation logic of the Contrast CLI, specifically affecting the security policies enforced by the Kata agent. The root cause is a deficiency in the CopyFile verification logic, which fails to properly constrain the destination path during file transfer operations between the host and the guest.\nThe Kata agent utilizes the VSOCK protocol to facilitate communication between the untrusted host and the guest workload. Under normal operating conditions, the agent expects validated requests to perform file operations. However, due to the flawed policy generated by the Contrast CLI in versions prior to 1.19.1, the validation checks are insufficient to prevent path traversal or directory breakout attempts.\nAn attacker with access to the host machine—specifically a process capable of communicating over the Kata agent VSOCK—can craft a malicious series of CopyFile requests. By manipulating the destination path parameters, an attacker can bypass intended access controls and write data to arbitrary locations within the guest's root filesystem.\nThe attack flow proceeds as follows: First, the attacker establishes a connection to the Kata agent via the VSOCK interface. Second, the attacker issues a specially crafted CopyFile request where the destination path is engineered to point to sensitive system files, configuration files, or binary executable paths within the guest environment. Because the verification policy lacks sufficient granularity, the agent executes the write operation as requested.\nPost-exploitation, an attacker can overwrite security-critical files such as /etc/shadow, system binaries, or application-specific configuration files. This capability allows the attacker to escalate privileges within the guest, achieve persistence, or manipulate the workload to disclose sensitive data, such as credentials or cryptographic keys stored in memory or on the disk. This effectively constitutes a full guest takeover, bypassing the intended security boundaries of the confidential-computing environment.\nThe vulnerability is limited to the agent policy implementation generated by the CLI. Therefore, the remediation focuses on replacing the flawed policy logic. Systems running version 1.19.1 and later are unaffected as the CLI logic has been corrected to strictly validate destination paths against a whitelist or constrained directory structure during CopyFile operations."
}