{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aedgeless_systemscontrast/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:edgeless_systems:contrast:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.2,"id":"CVE-2026-100833"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Contrast (1.14.0 - 1.23.0)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","cloud-security","confidential-computing"],"_cs_type":"advisory","_cs_vendors":["Edgeless Systems"],"content_html":"\u003cp\u003eContrast (edgelesssys/contrast) versions 1.14.0 through 1.23.0 are vulnerable to a security policy flaw that undermines the integrity of confidential containers. The issue stems from an accidental introduction of an allow_storage rule during a Kata Containers update, which inappropriately permits storage entries using the image_guest_pull driver without enforcing image digest verification. This vulnerability allows an attacker who already possesses access to the Kata agent API to replace legitimate container images with arbitrary payloads. Because the policy fails to validate the digest, the Kata runtime accepts the unauthorized image substitution, effectively neutralizing the confidential container protection mechanisms. This flaw is particularly relevant for Kubernetes environments where the agent API may be accessible to cluster administrators or other privileged actors within the threat model.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the execution of unauthorized code within a confidential container environment, undermining the integrity guarantees provided by the Edgeless Systems Contrast solution. This effectively permits a sandbox escape or privilege escalation within the container lifecycle management, potentially impacting the confidentiality and integrity of all data processed within the affected confidential container workloads.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade Edgeless Systems Contrast to version 1.23.1 or later immediately to apply the corrected runtime policy logic that enforces strict digest verification.\u003c/li\u003e\n\u003cli\u003eAudit Kubernetes cluster RBAC configurations to restrict access to the Kata agent API, limiting the potential pool of actors who could leverage this vulnerability.\u003c/li\u003e\n\u003cli\u003eReview current container deployment pipelines to ensure that integrity labels and image digests are strictly enforced at the orchestrator level, providing a layer of defense-in-depth while patches are deployed.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-27T03:03:54Z","date_published":"2026-09-27T03:03:54Z","id":"https://feed.craftedsignal.io/briefs/2026-09-contrast-digest-vulnerability/","summary":"Edgeless Systems Contrast versions 1.14.0 to 1.23.1 contain an insecure runtime policy configuration that allows attackers with Kata agent API access to substitute container images by bypassing digest verification.","title":"CVE-2026-100833: Insecure Image Digest Verification in Edgeless Systems Contrast","url":"https://feed.craftedsignal.io/briefs/2026-09-contrast-digest-vulnerability/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:edgeless_systems:contrast:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}