THREAT OPS › Threat News › [NVD] CVE-2026-50540 (CRITICAL 9.6) — Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Prior to version 4.0.0, kata-runtime is vulnerable to host code execution via an unvalidated configuration path annotation. The runt
[NVD] CVE-2026-50540 (CRITICAL 9.6) — Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Prior to version 4.0.0, kata-runtime is vulnerable to host code execution via an unvalidated configuration path annotation. The runt
CVE-2026-50540 CVSS: 9.6 CRITICAL Published: 2026-08-07T21:17:28.827
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Prior to version 4.0.0, kata-runtime is vulnerable to host code execution via an unvalidated configuration path annotation. The runtime accepts an arbitrary io.katacontainers.config_
Indicators of compromise
- CVE-2026-50540cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-50540