VDB
CVE-2026-87114
CVE-2026-87114
PUBLISHED
CVSS 7.1 HIGH
Reported by redhat · Published September 28, 2026
A flaw was found in kube-compare. When processing a 'container://' reference path, the tool incorrectly executes an untrusted container image's entrypoint instead of merely extracting data from a stopped container. This allows a remote attacker to achieve arbitrary code execution on the operator's workstation. If the Docker daemon requires elevated privileges, the untrusted code may execute with root-mediated daemon privileges, posing a significant security risk.
Risk Scores
CVSS 3.1
7.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat OpenShift Container Platform 4.19 | 1790632105 |
| Red Hat | Red Hat OpenShift Container Platform 4.20 | 1790707563 |
| Red Hat | Red Hat OpenShift Container Platform 4.21 | 1790707362 |
| Red Hat | Red Hat OpenShift Container Platform 4.22 | 1790718431 |
| Red Hat | Pen Drive Powered by Red Hat Lightspeed | |
| Red Hat | Red Hat OpenShift Container Platform 4.22 | 1790718431, 1790718431 |
| Red Hat | Red Hat OpenShift Container Platform 4 | |
| Red Hat | Red Hat OpenShift Container Platform 4.19 | 1790632105 |
| Red Hat | Pen Drive Powered by Red Hat Lightspeed | |
| Red Hat | Red Hat OpenShift Container Platform 4.20 | 1790707563 |
| Red Hat | Red Hat OpenShift Container Platform 4.21 | 1790707362, 1790707362 |
Timeline
- Sep 28, 2026 Coalition ESS Score
- Sep 28, 2026 CVE Published
- Sep 29, 2026 EPSS Score
- Oct 6, 2026 EPSS Score
- Oct 7, 2026 EPSS Score
- Oct 7, 2026 CVE Updated
- Oct 8, 2026 Distribution Patch
- Oct 8, 2026 Distribution Patch
- Oct 8, 2026 Distribution Patch
- Oct 8, 2026 Distribution Patch
- Oct 8, 2026 Security Advisory
- Oct 8, 2026 Security Advisory
References
- RHSA-2026:74381 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:74384 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:74430 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:74435 vendor-advisoryx_refsource_REDHAT
- vdb-entryx_refsource_REDHAT
- RHBZ#2522945 issue-trackingx_refsource_REDHAT