CVE-2026-24834
CVE-2026-24834 — Kata Container to Guest micro VM privilege escalation
Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. In versions prior to 3.27.0, an issue in Kata with Cloud Hypervisor allows a user of the container to modify the file system used by the Guest micro VM ultimately achieving arbitrary code execution as root in said VM. The current understanding is this doesn’t impact the security of the Host or of other containers / VMs running on that Host (note that arm64 QEMU lacks NVDIMM read-only support: It is believed that until the upstream QEMU gains this capability, a guest write could reach the image file). Version 3.27.0 patches the issue.
Published Updated Sources: cvelistV5, GitHub_M
Triage
Is it exploited, how likely is exploitation, what does it touch, and how severe do the scoring sources call it.
Exploitation
Unreported
no source claims exploitation
EPSS
0%
chance of exploitation in 30 days
CVSS base
9.4
CRITICAL
CISA SSVC assessment
Three decision points CISA publishes for the CVEs it assesses · SSVC 2.0.3. A stakeholder decision, not a severity score.
Exploitation
PoC
none · proof-of-concept · active
Automatable
No
can an attacker script all four kill-chain steps
Technical impact
Total
partial · total control of the vulnerable component
Affected scope
The catalog records vendors and products as separate lists, not pairs, so which product belongs to which vendor is not something this page can say.
Vendors (2)
Products (3)
Every base score collected
Sources score independently and disagree; each row says who scored it and under which version.
| Score | Version | Severity | Expl. | Impact | Source |
|---|---|---|---|---|---|
| 9.4 | CVSS 3.1 | CRITICAL | — | — | cvelistV5 |
Weakness & attack patterns
- CWE-732
- CWE-281
Attack patterns reported against this CVE. The ATT&CK techniques below are inferred from its weakness class.
- T1574.010Hijack Execution Flow: ServicesFile Permissions Weakness
- T1548Abuse Elevation Control Mechanism
- T1083File and Directory Discovery
References
6 on the record
- github.com/kata-containers/kata-containers/security/advisories/GHSA-wwj6-vghv-5p64
x_refsource_CONFIRM
- github.com/kata-containers/kata-containers/commit/6a672503973bf7c687053e459bfff8a9652e16bf
x_refsource_MISC
- github.com/kata-containers/kata-containers/releases/tag/3.27.0
x_refsource_MISC
- access.redhat.com/security/cve/CVE-2026-24834
vdb-entry, x_refsource_REDHAT
- bugzilla.redhat.com/show_bug.cgi?id=2441025
issue-tracking, x_refsource_REDHAT
- security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24834.json
x_sadp-csaf-vex
Elsewhere on this site
- kata containersevery CVE for this vendor
- redhatevery CVE for this vendor
- CWE-732other pages naming this weakness
Not in any source we poll
Listed rather than left blank: an empty field and an unmeasured one look identical on screen, and only one is a reason to look elsewhere.
- No confirmed IOCs, IP addresses, domains, file hashes, or malware artifacts supplied.
- No organization-specific asset inventory, compensating-control status, or patch deployment evidence supplied.
- No exploit packet captures, log samples, or incident case IDs supplied.