CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-50540

criticalCVSS 9.6covered by 2 sourcesfirst seen 2026-08-07
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Prior to version 4.0.0, kata-runtime is vulnerable to host code execution via an unvalidated configuration path annotation. The runtime accepts an arbitrary io.katacontainers.config_path pod annotation and loads the referenced host TOML file without restriction. As a result, a pod user who can place a file at a host-visible path can supply a configuration that selects an attacker-controlled hypervisor or virtio-fs daemon binary, executing code as root on the host. This issue is fixed in version 4.0.0.

CSIRTS triage

What
Config path annotation in Kata Containers allows arbitrary file loading via path traversal, bypassing intended file access restrictions.
Who is affected
Deployments of Kata Containers where untrusted container images can control configuration path annotations.
Urgency
Critical urgency; arbitrary file read/load leading to potential host compromise, container escape, or sensitive data disclosure.
Action
Upgrade Kata Containers to patched version immediately; restrict untrusted container image sources until patched.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-50540

Get an email if CVE-2026-50540 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-50540

CVE.org record

Embed the live status

CVE-2026-50540 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-50540 status](https://www.csirts.com/badge/CVE-2026-50540)](https://www.csirts.com/cve/CVE-2026-50540)