Skip to main content
Vulnerability Database/CVE-2026-100833

CVE-2026-100833: Contrast Container Image Substitution Flaw

CVE-2026-100833 is a container image substitution vulnerability in Contrast that allows attackers with Kata agent API access to replace container images with malicious payloads. This article covers technical details, affected versions from 1.14.0 to 1.23.1, security impact, and mitigation strategies.

Published:

CVE-2026-100833 Overview

CVE-2026-100833 affects Contrast (edgelesssys/contrast), a confidential computing framework for Kubernetes workloads built on Kata Containers. Versions 1.14.0 through 1.23.0 generate runtime policies that fail to validate container image digests when the image_guest_pull storage driver is in use. The flaw stems from a bad rebase during a Kata Containers update that introduced an overly permissive allow_storage rule. An attacker with access to the Kata agent API — including a Kubernetes cluster administrator in Contrast's threat model — can substitute the intended container image with a malicious payload. This substitution undermines the integrity guarantees that confidential containers are designed to enforce.

Critical Impact

An attacker inside Contrast's defined threat model can swap a trusted confidential container image for an attacker-controlled payload, breaking workload integrity and confidentiality.

Affected Products

  • Contrast (edgelesssys/contrast) version 1.14.0
  • Contrast releases through version 1.23.0
  • Confidential Kubernetes workloads relying on Contrast runtime policies with the image_guest_pull driver

Discovery Timeline

  • 2026-09-27 - CVE-2026-100833 published to the National Vulnerability Database (NVD)
  • 2026-09-30 - Last updated in NVD database

Technical Details for CVE-2026-100833

Vulnerability Analysis

Contrast generates Rego-based runtime policies that the Kata agent enforces inside confidential virtual machines. These policies constrain which images, mounts, and storage entries the agent will accept from the host. The vulnerability is an improper input validation flaw ([CWE-20]) in the generated policy, not in user-supplied input.

The generated policy includes an allow_storage rule that accepts storage entries using the image_guest_pull driver without verifying the associated image digest. As a result, the Kata agent inside the confidential guest cannot distinguish the expected image from a substitute presented by the host.

Successful exploitation lets an attacker execute arbitrary workload code inside what the operator believes is an attested confidential container, defeating the core trust boundary of the deployment.

Root Cause

A bad rebase during a Kata Containers dependency update accidentally introduced the permissive allow_storage branch. The affected rule treats any storage entry using the image_guest_pull driver as valid, bypassing the digest comparison that normally pins the container image. The remaining policy rules still execute, so a substituted image must satisfy them but is not bound to a specific content hash.

Attack Vector

An attacker with access to the Kata agent API — modeled in Contrast as a malicious or compromised Kubernetes cluster administrator — crafts a container pull request pointing at an attacker-controlled image. Because the policy omits digest verification for the image_guest_pull path, the Kata agent accepts the substituted image and launches it inside the confidential guest. The workload then runs attacker code with the privileges and secrets intended for the legitimate container.

No verified public proof-of-concept code is available. See the GitHub Security Advisory GHSA-m2qg-wrxv-h898 and the VulnCheck Advisory on Contrast for technical details.

Detection Methods for CVE-2026-100833

Indicators of Compromise

  • Confidential pods running container images whose digests do not match the manifest approved during policy generation.
  • Kata agent logs showing image_guest_pull operations that reference registries or image references outside the deployment's allowlist.
  • Unexpected process trees, outbound network connections, or file writes inside workloads that were expected to be read-only confidential containers.

Detection Strategies

  • Compare the image digest reported by the running confidential pod against the digest embedded in the Contrast manifest used to generate the policy.
  • Audit all deployed Contrast runtime policies for allow_storage rules that accept the image_guest_pull driver without a digest check.
  • Treat any mismatch between the attested policy hash and the policy version shipped in Contrast 1.23.1 or later as suspicious.

Monitoring Recommendations

  • Centralize Kubernetes audit logs and Kata agent logs so image pull and policy enforcement events can be correlated.
  • Alert on confidential workload admission events that originate from cluster-admin service accounts or that modify pod specs post-admission.
  • Baseline network egress from confidential pods and alert on deviations that could indicate a substituted payload.

How to Mitigate CVE-2026-100833

Immediate Actions Required

  • Upgrade Contrast to version 1.23.1 or later across all clusters that run confidential workloads.
  • Regenerate runtime policies and manifests for every affected deployment using the patched release, then redeploy workloads so the new policy is attested.
  • Rotate any secrets, keys, or tokens that were provisioned into confidential containers while vulnerable versions were in use.

Patch Information

The fix is included in Contrast version 1.23.1. The patched release restores digest verification for storage entries that use the image_guest_pull driver. Refer to the GitHub Security Advisory GHSA-m2qg-wrxv-h898 for the authoritative fix notes and upgrade guidance.

Workarounds

  • Restrict access to the Kata agent API and tightly scope cluster-admin privileges on clusters hosting confidential workloads until upgrades complete.
  • Avoid using the image_guest_pull driver in policies generated by vulnerable Contrast versions; prefer configurations that pin images by digest through alternative storage paths.
  • Enforce out-of-band image digest attestation (for example, via signed deployment pipelines) so substituted images can be detected before workloads consume sensitive data.
bash
# Verify installed Contrast CLI version and upgrade to the fixed release
contrast version
# Upgrade to the patched version 1.23.1 or later, then regenerate policies
contrast generate --reference-values <platform> deployment/
contrast set deployment/

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.