Description
Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.4.1, a recovering Coordinator does not verify the seed supplied by the recovering party. An attacker can therefore stand up a rogue Coordinator whose manifest passes validation but whose secret seed is attacker-controlled. If network traffic is redirected from the legitimate Coordinator to the attacker's Coordinator, a workload owner can be impersonated when they either set a new manifest without comparing the returned root CA certificate against the existing one (the default behavior of the contrast CLI) or verify the Coordinator without comparing the root CA certificate against a trusted reference. Under these conditions the attacker can issue certificates that chain back to the rogue Coordinator's root CA and recover arbitrary workload secrets of workloads deployed after the attack. Secrets of the legitimate Coordinator (seed, workload secrets, CA), workload integrity, and certificates chaining to the mesh CA are not affected.
Published: 2026-09-27
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Impersonation of workload owners and recovery of arbitrary workload secrets
Action: Immediate Patch
AI Analysis

Impact

Contrast is an open‑source confidential‑computing runtime for Kubernetes. Versions prior to 1.4.1 do not verify the seed supplied during Coordinator recovery. An attacker can therefore launch a rogue Coordinator whose manifest is accepted as valid, but whose secret seed is attacker‑controlled. If traffic is redirected from the legitimate Coordinator to the attacker’s Coordinator, a workload owner can be impersonated when the workload owner either sets a new manifest without checking the returned root CA certificate against the existing one (the default contrast CLI behavior) or verifies the Coordinator without comparing the root CA certificate against a trusted reference. Under those conditions the attacker can issue certificates that chain back to the rogue Coordinator’s root CA and recover arbitrary workload secrets of workloads deployed after the attack. Secrets of the legitimate Coordinator (seed, workload secrets, CA), workload integrity, and certificates chaining to the mesh CA remain unaffected.

Affected Systems

The affected vendor is Edgeless Systems, product Contrast, as distributed on the Kubernetes platform. The vulnerability applies to all Contrast releases before version 1.4.1. No specific patch version numbers are listed beyond this, so the advisory recommends upgrading to 1.4.1 or newer to mitigate the problem.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity environment. The EPSS score is not available, so the current exploitation likelihood cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. Potential attackers must control or redirect network traffic to the Coordinator and exploit the coordinator recovery mechanism; therefore threat production requires some network access or administrative capabilities. The attack path allows attackers to impersonate workload owners and recover workload secrets, which could lead to confidentiality breaches and unauthorized credential use.

Generated by OpenCVE AI on September 27, 2026 at 03:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Contrast to version 1.4.1 or later, where seed verification during Coordinator recovery is enforced.
  • Configure the contrast CLI to validate the root CA certificate against a trusted reference rather than using the default behavior, and reject any Coordinator that does not present the expected certificate.
  • Implement network segmentation and traffic monitoring to detect and prevent unauthorized traffic redirection from the legitimate Coordinator to a rogue Coordinator.

Generated by OpenCVE AI on September 27, 2026 at 03:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 27 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
Description Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.4.1, a recovering Coordinator does not verify the seed supplied by the recovering party. An attacker can therefore stand up a rogue Coordinator whose manifest passes validation but whose secret seed is attacker-controlled. If network traffic is redirected from the legitimate Coordinator to the attacker's Coordinator, a workload owner can be impersonated when they either set a new manifest without comparing the returned root CA certificate against the existing one (the default behavior of the contrast CLI) or verify the Coordinator without comparing the root CA certificate against a trusted reference. Under these conditions the attacker can issue certificates that chain back to the rogue Coordinator's root CA and recover arbitrary workload secrets of workloads deployed after the attack. Secrets of the legitimate Coordinator (seed, workload secrets, CA), workload integrity, and certificates chaining to the mesh CA are not affected.
Title Contrast before 1.4.1 Coordinator Impersonation via Unauthenticated Recovery
Weaknesses CWE-285
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-27T01:28:27.915Z

Reserved: 2026-09-27T00:18:28.650Z

Link: CVE-2025-71426

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-27T02:17:17.160

Modified: 2026-09-27T02:17:17.160

Link: CVE-2025-71426

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-27T03:30:20Z

Weaknesses