CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-77176

highCVSS 8.1covered by 2 sourcesfirst seen 2026-08-11
A flaw was found in Kata Containers. In configurations utilizing genpolicy for Confidential Containers guest protection, a malicious host operator can exploit insufficient validation of CreateContainer mount and storage rules. This allows them to mount arbitrary container-rootfs paths over sensitive host locations or provision arbitrary content, potentially exposing confidential information or enabling the acceptance of attacker-controlled input.

CSIRTS triage

What
Insufficient validation of createcontainer mount and storage rules in genpolicy allows privilege escalation or container escape.
Who is affected
Kata containers deployments using genpolicy for container creation.
Urgency
High severity (CVSS 8.1); escape or privilege escalation from containers is a critical concern.
Action
Apply security update for CVE-2026-77176 to kata-containers immediately.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-77176

Get an email if CVE-2026-77176 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-77176

CVE.org record

Embed the live status

CVE-2026-77176 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-77176 status](https://www.csirts.com/badge/CVE-2026-77176)](https://www.csirts.com/cve/CVE-2026-77176)