Junglewise Threat Intelligence

CVE-2026-100838: Edgeless Systems Contrast arbitrary filesystem write in CopyFile policy

CVE-2026-100838 · Severity: high · CVSS 8.1 · Published 2026-09-27

Technologies: Edgeless Systems Contrast. Vendors: Edgeless Systems.

Executive brief

Contrast is a confidential-computing runtime that protects containerized workloads in Kubernetes by isolating them from the host. A flaw in versions before 1.19.1 allows a malicious process on the host to write arbitrary files to the guest filesystem and access sensitive data, resulting in complete compromise of the isolated workload. This enables attackers to steal secrets or modify applications running inside the protected container.

Technical details

The Kata agent policies generated by the Contrast CLI contained improper symlink resolution in CopyFile verification (CWE-59), allowing arbitrary writes to the guest root filesystem. An attacker with VSOCK connectivity to the Kata agent (no authentication required) can issue crafted CopyFile requests to overwrite security-critical files or exfiltrate sensitive data. The fix is available in version 1.19.1, with a policy-only workaround available for users unable to upgrade immediately.

Affected products

  • Edgeless Systems Contrast before 1.19.1

Timeline

  • 2026-09-27: disclosed
  • 2026-04-23: patched: Version 1.19.1 released

References

Related threats