What is CVE-2026-50540?
A vulnerability in Kata Containers versions prior to 4.0.0 allows host code execution via an unvalidated configuration path annotation in the kata-runtime. Immediate update to version 4.0.0 is required to mitigate the risk.
Azərbaycanca: Kata Containers-in 4.0.0-dan əvvəlki versiyalarında, kata-runtime komponenti host kod icrasına səbəb ola biləcək zəiflik aşkarlanıb. Bu boşluq yoxlanılmamış konfiqurasiya yolu annotasiyası vasitəsilə istismar edilir, təcili olaraq 4.0.0 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-20
FAQ2
Which software is affected by CVE-2026-50540 and what versions are vulnerable?
This vulnerability affects Kata Containers versions prior to 4.0.0. Specifically, the kata-runtime component is at risk.
What is the primary recommended action to remediate CVE-2026-50540?
To mitigate the risk, an immediate update of Kata Containers to version 4.0.0 is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.