{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/kube-compare/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:kube_compare:kube_compare:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-87114"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["kube-compare (all versions)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["kube-compare"],"content_html":"\u003cp\u003eCVE-2026-87114 is a high-severity arbitrary code execution vulnerability identified in the kube-compare utility. The flaw exists in the tool's handling of 'container://' reference paths. When the tool is instructed to process a malicious container image reference, it incorrectly triggers the execution of the image's entrypoint rather than safely extracting the required data from the stopped container.\u003c/p\u003e\n\u003cp\u003eThis behavior exposes the operator's workstation to remote code execution. Because kube-compare often interacts directly with the local Docker daemon, there is a significant risk of privilege escalation. If the Docker daemon is configured with root privileges, the malicious code executed by the container image may run with corresponding elevated system access, allowing for complete host compromise. This issue affects any environment where users leverage kube-compare to inspect untrusted or potentially compromised container images.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability poses a high risk of remote code execution on the workstation of any developer or administrator using the affected version of kube-compare. In environments where the Docker daemon runs with root privileges, this impact scales to full host compromise. Organizations using kube-compare for CI/CD pipelines or local development inspection workflows are at the highest risk, as they are likely to encounter untrusted container images during their build or troubleshooting processes.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update kube-compare to the latest patched version that addresses CVE-2026-87114.\u003c/li\u003e\n\u003cli\u003eAudit CI/CD pipelines and developer workstations to identify instances where kube-compare is used to inspect container images from untrusted sources.\u003c/li\u003e\n\u003cli\u003eEnforce the principle of least privilege by ensuring the Docker daemon is configured to run without unnecessary root privileges, limiting the potential impact of an exploited container entrypoint.\u003c/li\u003e\n\u003cli\u003eImplement strict image provenance checks to ensure only trusted container images are processed by developer utilities.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-28T18:20:47Z","date_published":"2026-09-28T18:20:47Z","id":"https://feed.craftedsignal.io/briefs/2026-09-kube-compare-rce/","summary":"A vulnerability in kube-compare (CVE-2026-87114) allows remote code execution on the operator workstation when processing a crafted 'container://' reference path.","title":"Arbitrary Code Execution in kube-compare via Malicious Container References","url":"https://feed.craftedsignal.io/briefs/2026-09-kube-compare-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Kube-Compare","version":"https://jsonfeed.org/version/1.1"}