CVE 2026 87114
A flaw was found in kube-compare. When processing a 'container://' reference path, the tool incorrectly executes an untrusted container image's entrypoint instead of merely extracting data from a stopped container. This allows a remote attacker to achieve arbitrary code execution on the operator's workstation. If the Docker daemon requires elevated privileges, the untrusted code may execute with root-mediated daemon privileges, posing a significant security risk.
This Important vulnerability in kube-compare allows arbitrary code execution on an operator's workstation. When kube-compare processes a malicious container:// reference, and docker is configured to require sudo for daemon access, the untrusted image's entrypoint executes with root-mediated privileges. This risk is specific to environments where kube-compare interacts with docker requiring elevated permissions.
To mitigate this issue, users of `kube-compare` should ensure that any container images referenced via the `container://` scheme are from trusted sources. Avoid using untrusted or unverified container images as reference paths. If `docker` is configured to require `sudo` for daemon socket access, consider reviewing `sudo` policies to limit `docker` command execution to trusted users and contexts.
Bugzilla 2522945 : kube-compare: container:// reference extraction runs the image entrypoint and silently escalates to sudo
CWE-829 : Inclusion of Functionality from Untrusted Control Sphere
Common Vulnerability Scoring System (CVSS) Score Details
Info alert: Important note
CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications ).
The following CVSS metrics and score provided are preliminary and subject to review.
CVSS v3 Score Breakdown
Red Hat: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Understanding the Weakness (CWE)
Confidentiality,Integrity,Availability
Technical Impact: Execute Unauthorized Code or Commands
An attacker could insert malicious functionality into the program by causing the program to download code that the attacker has placed into the untrusted control sphere, such as a malicious web site. This could enable the injection of malware, information exposure by granting excessive privileges or permissions to the untrusted functionality, DOM-based XSS vulnerabilities, stealing user's cookies, open redirect to malware (CWE-601), etc.
Frequently Asked Questions
"Under investigation" doesn't necessarily mean that the product is affected by this vulnerability. It only means that our Analysis Team is still working on determining whether the product is affected and how it is affected.
The term 'Affected' means that our Analysis team has determined that this product, such as Red Hat Enterprise Linux 8 or OpenShift Container Platform 4, is affected by this vulnerability and a fix may be released to address this issue in the near future. This includes all minor releases of this product unless noted otherwise in the Statement text.
Upgrade to a supported product version that includes a fix for this vulnerability (recommended).
Apply a mitigation (if one exists).
Customers with the Technical Account Manager (TAM) RHEL Security Select Add-on can review this CVE directly with their TAM.
Apply a mitigation (if one exists).
Red Hat Engineering focuses on addressing high-priority issues based on the impact and product lifecycle expectations. Therefore, lower-priority issues will not receive immediate fixes.
Customers with the technical account manager (TAM) RHEL Security Select Add-on can review this CVE directly with their TAM.
Not sure what something means? Check out our Security Glossary .
For clarification or corrections, please Red Hat Product Security .
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
