Container Image Vulnerability in Contrast by Edgeless Systems
CVE-2026-100833

7.6HIGH

Key Information:

Status
Vendor
CVE Published:
27 September 2026

What is CVE-2026-100833?

The Contrast product by Edgeless Systems suffers from a vulnerability where certain versions create runtime policies that fail to properly validate container image substitutions. Due to a bad rebase during a Kata Containers update, an allow_storage rule was introduced, permitting unwarranted storage entries using the image_guest_pull driver without adequate verification of the image digest. This flaw allows attackers, particularly those with administrative access to the Kata agent API, to exploit the system by substituting container images with malicious payloads, thereby compromising the integrity of confidential containers and breaching expected security measures.

Affected Version(s)

contrast 1.14.0 < 1.23.1

contrast 1.23.1

References

CVSS V4

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

sespiros
burgerdev
.