A high-severity vulnerability tracked as CVE-2026-50540 affects Kata Containers versions prior to 4.0.0, allowing a low-privileged attacker to trigger host code execution as root through the kata-runtime component. The issue stems from support for the pod annotation io.katacontainers.config_path, which let the runtime load an arbitrary host TOML configuration file without sufficient validation or restriction. If an attacker can place a file at a host-visible path, they can point Kata Containers to attacker-controlled settings and select a malicious hypervisor or virtio-fs daemon binary.
Kata Containers addressed the flaw by removing support for the config_path sandbox annotation override in a code change that deleted the annotation constant, helper logic, tests, and documentation tied to that behavior. The updated runtime now resolves configuration from the KATA_CONF_FILE environment variable, shimv2 create task options, and default runtime configuration paths instead. The vulnerability is associated with path traversal and improper input validation weaknesses and carries a CVSS v3.1 score vector of AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
GitHub security advisories received CVE-2026-50540 on August 7, 2026 for a Kata Containers vulnerability in `kata-runtime` that allowed arbitrary host TOML configuration loading via the `io.katacontainers.config_path` annotation. The issue affected versions prior to 4.0.0 and could lead to host code execution as root; the CVE record states it was fixed in version 4.0.0.
A Kata Containers code change removed support for the `io.katacontainers.config_path` pod sandbox annotation as a runtime configuration override across Go and Rust components, tests, and documentation. This change eliminated annotation-based loading of host TOML configuration files and updated configuration precedence to use `KATA_CONF_FILE`, shimv2 task options, and default paths.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.