A flaw was found in kube-compare. When processing a 'container://' reference path, the tool incorrectly executes an untrusted container image's entrypoint instead of merely extracting data from a stopped container. This allows a remote attacker to achieve arbitrary code execution on the operator's workstation. If the Docker daemon requires elevated privileges, the untrusted code may execute with root-mediated daemon privileges, posing a significant security risk.

Project Subscriptions

Vendors Products
Openshift Subscribe
Pdrive Lightspeed Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

To mitigate this issue, users of `kube-compare` should ensure that any container images referenced via the `container://` scheme are from trusted sources. Avoid using untrusted or unverified container images as reference paths. If `docker` is configured to require `sudo` for daemon socket access, consider reviewing `sudo` policies to limit `docker` command execution to trusted users and contexts.

History

Mon, 28 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in kube-compare. When processing a 'container://' reference path, the tool incorrectly executes an untrusted container image's entrypoint instead of merely extracting data from a stopped container. This allows a remote attacker to achieve arbitrary code execution on the operator's workstation. If the Docker daemon requires elevated privileges, the untrusted code may execute with root-mediated daemon privileges, posing a significant security risk.
Title Kube-compare: container:// reference extraction runs the image entrypoint and silently escalates to sudo
First Time appeared Redhat
Redhat openshift
Redhat pdrive Lightspeed
Weaknesses CWE-829
CPEs cpe:/a:redhat:openshift:4
cpe:/a:redhat:pdrive_lightspeed:1
Vendors & Products Redhat
Redhat openshift
Redhat pdrive Lightspeed
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-28T16:49:04.008Z

Reserved: 2026-09-08T20:41:51.624Z

Link: CVE-2026-87114

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-28T17:17:51.530

Modified: 2026-09-28T17:17:51.530

Link: CVE-2026-87114

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T18:45:05Z

Weaknesses