VDB

CVE-2026-87114

CVE-2026-87114 PUBLISHED CVSS 7.1 HIGH

Reported by redhat · Published September 28, 2026

A flaw was found in kube-compare. When processing a 'container://' reference path, the tool incorrectly executes an untrusted container image's entrypoint instead of merely extracting data from a stopped container. This allows a remote attacker to achieve arbitrary code execution on the operator's workstation. If the Docker daemon requires elevated privileges, the untrusted code may execute with root-mediated daemon privileges, posing a significant security risk.

Risk Scores

CVSS 3.1
7.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

Affected Products

VendorProductVersions
Red HatRed Hat OpenShift Container Platform 4.191790632105
Red HatRed Hat OpenShift Container Platform 4.201790707563
Red HatRed Hat OpenShift Container Platform 4.211790707362
Red HatRed Hat OpenShift Container Platform 4.221790718431
Red HatPen Drive Powered by Red Hat Lightspeed
Red HatRed Hat OpenShift Container Platform 4.221790718431, 1790718431
Red HatRed Hat OpenShift Container Platform 4
Red HatRed Hat OpenShift Container Platform 4.191790632105
Red HatPen Drive Powered by Red Hat Lightspeed
Red HatRed Hat OpenShift Container Platform 4.201790707563
Red HatRed Hat OpenShift Container Platform 4.211790707362, 1790707362

Timeline

  • Sep 28, 2026 Coalition ESS Score
  • Sep 28, 2026 CVE Published
  • Sep 29, 2026 EPSS Score
  • Oct 6, 2026 EPSS Score
  • Oct 7, 2026 EPSS Score
  • Oct 7, 2026 CVE Updated
  • Oct 8, 2026 Distribution Patch
  • Oct 8, 2026 Distribution Patch
  • Oct 8, 2026 Distribution Patch
  • Oct 8, 2026 Distribution Patch
  • Oct 8, 2026 Security Advisory
  • Oct 8, 2026 Security Advisory

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›