No analysis available yet.
Vendor Workaround
To mitigate this issue, users of `kube-compare` should ensure that any container images referenced via the `container://` scheme are from trusted sources. Avoid using untrusted or unverified container images as reference paths. If `docker` is configured to require `sudo` for daemon socket access, consider reviewing `sudo` policies to limit `docker` command execution to trusted users and contexts.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 28 Sep 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in kube-compare. When processing a 'container://' reference path, the tool incorrectly executes an untrusted container image's entrypoint instead of merely extracting data from a stopped container. This allows a remote attacker to achieve arbitrary code execution on the operator's workstation. If the Docker daemon requires elevated privileges, the untrusted code may execute with root-mediated daemon privileges, posing a significant security risk. | |
| Title | Kube-compare: container:// reference extraction runs the image entrypoint and silently escalates to sudo | |
| First Time appeared |
Redhat
Redhat openshift Redhat pdrive Lightspeed |
|
| Weaknesses | CWE-829 | |
| CPEs | cpe:/a:redhat:openshift:4 cpe:/a:redhat:pdrive_lightspeed:1 |
|
| Vendors & Products |
Redhat
Redhat openshift Redhat pdrive Lightspeed |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-28T16:49:04.008Z
Reserved: 2026-09-08T20:41:51.624Z
Link: CVE-2026-87114
No data.
Status : Received
Published: 2026-09-28T17:17:51.530
Modified: 2026-09-28T17:17:51.530
Link: CVE-2026-87114
No data.
OpenCVE Enrichment
No data.
-
CWE-829
Inclusion of Functionality from Untrusted Control Sphere