CVE-2026-100838 Overview
CVE-2026-100838 affects Contrast, a confidential-computing runtime for Kubernetes developed by Edgeless Systems. The flaw resides in the Kata agent policies generated by the Contrast command-line interface (CLI). A verification weakness in the CopyFile handler allows arbitrary writes to the guest root filesystem. An attacker on the untrusted host who can reach the Kata agent VSOCK interface can overwrite security-critical files inside the confidential guest. The flaw maps to [CWE-59: Improper Link Resolution Before File Access (Link Following)] and enables full guest takeover. Versions prior to 1.19.1 are affected.
Critical Impact
Attackers with adjacent-network access to the Kata agent VSOCK can overwrite arbitrary files inside the confidential guest and compromise the workload.
Affected Products
- Edgeless Systems Contrast versions prior to 1.19.1
- Contrast CLI-generated Kata agent policies
- Confidential Kubernetes workloads deployed through Contrast
Discovery Timeline
- 2026-09-27 - CVE-2026-100838 published to NVD
- 2026-09-30 - Last updated in NVD database
Technical Details for CVE-2026-100838
Vulnerability Analysis
Contrast relies on Kata Containers to run confidential workloads inside hardware-isolated virtual machines. The Contrast CLI generates Rego policies that constrain the Kata agent's host-facing API, including the CopyFile request used to stage files into the guest. The policy's CopyFile verification fails to account for symbolic links already present on the guest filesystem. An attacker-controlled host process that reaches the Kata agent VSOCK can issue a sequence of CopyFile requests whose destination paths resolve through symlinks to arbitrary locations. The agent then writes attacker-chosen content outside the intended staging directory, including security-critical files inside the guest root filesystem. The result is a complete subversion of the confidentiality and integrity guarantees that Contrast is designed to enforce.
Root Cause
The generated Rego policy validates the literal destination path supplied in each CopyFile request but does not resolve or constrain symbolic links on the target filesystem. Because symlinks created earlier in the request stream are followed during subsequent writes, path validation is bypassed at use time.
Attack Vector
Exploitation requires network-adjacent access to the Kata agent VSOCK channel on the untrusted host that runs the confidential pod. The attacker chains CopyFile operations: an initial write plants a symlink pointing to a sensitive target, and a follow-up write delivers attacker-controlled content through that symlink. Suitable targets include authentication files, binaries on the guest PATH, or workload configuration that can be weaponized to exfiltrate secrets held inside the trusted execution environment. No credentials or user interaction are required.
No verified public exploit code is available. See the GitHub Security Advisory and the VulnCheck Advisory on Contrast for technical details.
Detection Methods for CVE-2026-100838
Indicators of Compromise
- Unexpected CopyFile requests to the Kata agent VSOCK targeting paths outside the normal staging directory, such as /etc, /usr/bin, or workload secret mount points.
- Newly created symbolic links inside guest images that point to security-sensitive files such as /etc/shadow, /etc/ssh/, or application configuration directories.
- Modifications to guest binaries or configuration files that occur after pod startup but before workload entrypoint execution.
Detection Strategies
- Audit the Contrast CLI version used to generate deployed policies and flag any policy produced by a version earlier than 1.19.1.
- Compare runtime guest filesystem state against the expected image manifest to detect unauthorized writes delivered through CopyFile.
- Enable Kata agent request logging on the untrusted host and alert on CopyFile operations whose destination resolves through a symlink.
Monitoring Recommendations
- Collect Kubernetes admission events and Contrast policy hashes to track which workloads run with vulnerable policies.
- Forward VSOCK and Kata agent logs into a centralized data lake for correlation with workload-level anomalies.
- Monitor for host processes other than the containerd-shim establishing VSOCK sessions with the Kata agent.
How to Mitigate CVE-2026-100838
Immediate Actions Required
- Upgrade the Contrast CLI and runtime to version 1.19.1 or later and regenerate all deployment policies.
- Redeploy existing confidential workloads so they attest against the fixed policy before accepting new secrets.
- Rotate any secrets, keys, or credentials that were provisioned into guests running under vulnerable policies.
Patch Information
Edgeless Systems addressed the flaw in Contrast 1.19.1. The fix hardens the generated Rego policy so that CopyFile destinations cannot be redirected through symbolic links on the guest filesystem. Refer to the GitHub Security Advisory GHSA-rh99-wc69-c255 for the authoritative patch notes.
Workarounds
- Users unable to upgrade can apply the equivalent Rego policy fix and pass it to contrast generate --policy as documented in the advisory.
- Restrict host-side access to the Kata agent VSOCK so that only the expected shim process can establish sessions.
- Monitor and alert on any CopyFile activity targeting paths outside the designated staging directory.
# Regenerate deployment manifests with the fixed CLI and policy
contrast generate --policy ./fixed-policy.rego ./deployment/
kubectl apply -f ./deployment/
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.