CVE-2026-87114
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Summary
A flaw was found in kube-compare. When processing a 'container://' reference path, the tool incorrectly executes an untrusted container image's entrypoint instead of merely extracting data from a stopped container. This allows a remote attacker to achieve arbitrary code execution on the operator's workstation. If the Docker daemon requires elevated privileges, the untrusted code may execute with root-mediated daemon privileges, posing a significant security risk.
Affected Software
| Vendor | Product | Version Range | Status |
|---|
Weaknesses
- CWE-829: Inclusion of Functionality from Untrusted Control Sphere
Workarounds
To mitigate this issue, users of kube-compare should ensure that any container images referenced via the container:// scheme are from trusted sources. Avoid using untrusted or unverified container images as reference paths. If docker is configured to require sudo for daemon socket access, consider reviewing sudo policies to limit docker command execution to trusted users and contexts.
References
- https://access.redhat.com/security/cve/CVE-2026-87114
- https://bugzilla.redhat.com/show_bug.cgi?id=2522945
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.