Container Image Vulnerability in Contrast by Edgeless Systems
CVE-2026-100833
7.6HIGH
What is CVE-2026-100833?
The Contrast product by Edgeless Systems suffers from a vulnerability where certain versions create runtime policies that fail to properly validate container image substitutions. Due to a bad rebase during a Kata Containers update, an allow_storage rule was introduced, permitting unwarranted storage entries using the image_guest_pull driver without adequate verification of the image digest. This flaw allows attackers, particularly those with administrative access to the Kata agent API, to exploit the system by substituting container images with malicious payloads, thereby compromising the integrity of confidential containers and breaching expected security measures.
Affected Version(s)
contrast 1.14.0 < 1.23.1
contrast 1.23.1
