CVE-2026-24834 is a high-severity vulnerability affecting Kata Containers versions prior to 3.27.0, specifically impacting Cloud Hypervisor integration. An authenticated container user can modify the guest micro VM's filesystem, leading to arbitrary code execution as root within that VM. The CVSS score is 8.8 (High), indicating a local attack vector with low complexity and high impact on confidentiality, integrity, and availability within the guest VM. While there is no evidence of active exploitation, public exploit code, or KEV listing, the vulnerability has garnered significant community discussion with 22 mentions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.27.0CPE matchmatch criteria | cpe:2.3:a:katacontainers:kata_containers:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
containerd-shim-kata-v2: Kata Containers: Arbitrary code execution in guest virtual machine via file system modification
Feb 19, 2026Kata Container to Guest micro VM privilege escalation
Feb 19, 2026Kata Container to Guest micro VM privilege escalation
Feb 10, 2026