Back Redpacketsecurity CVE Alert: CVE-2026-87114 – Red Hat
A flaw was found in kube-compare. When processing a ‘container://’ reference path, the tool incorrectly executes an untrusted container image’s entrypoint instead of merely extracting data from a stopped container. This allows a remote attacker to achieve arbitrary code execution on the operator’s workstation. If the Docker daemon requires elevated privileges, the untrusted code may execute with root-mediated daemon privileges, posing a significant security risk.
**Risk verdict:** High risk for teams that process untrusted container references; KEV, SSVC exploitation, PoC and EPSS data were not supplied, so active exploitation and urgency cannot be confirmed.
**Why this matters:** A successful attack can compromise the operator’s workstation and expose local credentials, configuration files and other sensitive data. Where Docker access is mediated by elevated privileges, the impact may extend to host-level control, giving an attacker a foothold for further access.
**Most likely attack path:** An attacker supplies or persuades an operator to use a crafted `container://` reference, then waits for the tool to process it. The attack is local, low complexity and needs no prior privileges, but does require user interaction. Scope is assessed as unchanged; elevated daemon access could nevertheless increase impact on the workstation, while lateral movement would depend on credentials and network access available there.
**Who is most exposed:** Teams running container comparison or scanning workflows on developer, administrator or CI workstations are the main concern, especially where references can come from external repositories.
Review command history and process telemetry for unexpected image entrypoint execution during reference processing.
Alert on scanner-launched containers or unexpected child processes.
Check Docker daemon logs and sudo records for associated activity.
Investigate unusual outbound connections or credential access from operator workstations.
Mitigation and prioritisation
Verify affected installations and apply the vendor’s fixed build when available; confirm status for packages with uncertain applicability.
Until patched, accept only verified, trusted container references.
Restrict Docker socket and sudo access to authorised users and required workflows.
Roll out changes through normal change control, prioritising exposed operator and CI systems.
A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.
If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
