CVE-2026-87114

Summary

A flaw was found in kube-compare. When processing a 'container://' reference path, the tool incorrectly executes an untrusted container image's entrypoint instead of merely extracting data from a stopped container. This allows a remote attacker to achieve arbitrary code execution on the operator's workstation. If the Docker daemon requires elevated privileges, the untrusted code may execute with root-mediated daemon privileges, posing a significant security risk.

Affected Software

VendorProductVersion RangeStatus

Weaknesses

  • CWE-829: Inclusion of Functionality from Untrusted Control Sphere

Workarounds

To mitigate this issue, users of kube-compare should ensure that any container images referenced via the container:// scheme are from trusted sources. Avoid using untrusted or unverified container images as reference paths. If docker is configured to require sudo for daemon socket access, consider reviewing sudo policies to limit docker command execution to trusted users and contexts.

References