LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-44210

katacontainers · kata containers

Published
CVSS9.9
Severitycritical
WeaknessCWE-88
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Description

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Versions prior to 3.31.0 ship with a default configuration that allows pod creators to inject arbitrary command-line arguments into the virtiofsd process through the `io.katacontainers.config.hypervisor.virtio_fs_extra_args` pod annotation. By injecting `-o source=/` along with `--no-announce-submounts` and `--sandbox=none`, an attacker can override the virtiofsd shared directory to serve the entire host root filesystem into the guest VM. Combined with the `kernel_params` annotation (also enabled by default) to activate the agent debug console, t

References

← Back to the CVE Tracker

Our coverage of CVE-2026-44210

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-44210.