SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-77176

HIGH · CVSS 8.1 EPSS 0.41% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-20 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

A vulnerability in Kata Containers allows a malicious host operator to exploit inadequate validation of mount and storage rules in configurations using genpolicy for Confidential Containers guest protection. This can lead to arbitrary container-root filesystem paths being mounted over sensitive host locations, risking exposure of confidential information and enabling the injection of attacker-controlled content. Organizations utilizing Kata Containers for sensitive workloads should prioritize addressing this issue to safeguard their data integrity and confidentiality.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-77176
Severity
HIGH
CVSS
8.1
EPSS
0.41%

Original NVD Description

A flaw was found in Kata Containers. In configurations utilizing genpolicy for Confidential Containers guest protection, a malicious host operator can exploit insufficient validation of CreateContainer mount and storage rules. This allows them to mount arbitrary container-rootfs paths over sensitive host locations or provision arbitrary content, potentially exposing confidential information or enabling the acceptance of attacker-controlled input.