Improper Neutralization of Argument Delimiters in a Command in Kata Containers - CVE-2026-44210
Published: May 22, 2026
Kata Containers
Detailed vulnerability description
The vulnerability allows a remote user to read and write arbitrary files on the host.
The vulnerability exists due to improper neutralization of argument delimiters in a command in the virtiofsd argument handling for the io.katacontainers.config.hypervisor.virtio_fs_extra_args pod annotation when processing user-supplied pod annotations. A remote user can inject crafted virtiofsd and kernel parameters to read and write arbitrary files on the host.
Exploitation requires the ability to create pods on a Kubernetes cluster using Kata Containers with the default annotation configuration enabled.