CVE-2026-64676: Kata Containers: Unauthorized mem-agent ttRPC methods let an untrusted host tamper with confidential-guest memory

Published Aug 7, 2026
·
Updated

Kata Containers is an open source implementation of lightweight Virtual Machines (VMs) that perform like containers. In versions prior to 4.0.0, the kata-agent is vulnerable to an authorization bypass in confidential-guest memory management. In Confidential Containers (CoCo) deployments, the kata-agent enforces an OPA/Rego-based AgentPolicy that must authorize every ttRPC API call, forming the security boundary that prevents an untrusted host from directing the confidential guest. Two ttRPC methods introduced with the mem-agent feature are missing this authorization check, so an untrusted host can invoke them unconditionally regardless of the guest's policy configuration. When mem-agent is enabled (off by default), this lets the host tamper with in-guest memory management by forcing swap, aggressive eviction, or compaction, resulting in attacker-controlled availability and performance degradation of the confidential workload entirely outside the agent-policy boundary. The impact does not include memory disclosure or code execution, and severity is bounded by the precondition that mem-agent must be explicitly enabled. This issue is fixed in version 4.0.0.

Affected Software

2 affected components
Kata Containers Kata Containers<4.0.0
Kata Containers=4.0.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Kata Containers (kata-agent / confidential-guest memory management via mem-agent) to a version that resolves this vulnerability.

    Fixed in 4.0.0

Event History

Aug 7, 2026
CVE Published
via MITRE·09:47 PM
Data Sourced
via MITRE·09:47 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-64676?

CVE-2026-64676 has a medium severity rating of 5.7.

2

How do I fix CVE-2026-64676?

To mitigate CVE-2026-64676, upgrade Kata Containers to version 4.0.0 or later.

3

What type of vulnerability is found in CVE-2026-64676?

CVE-2026-64676 represents an authorization bypass vulnerability in the kata-agent.

4

Who is affected by CVE-2026-64676?

Users of Kata Containers versions prior to 4.0.0, particularly in Confidential Containers deployments, are affected by CVE-2026-64676.

5

What does CVE-2026-64676 affect in Kata Containers?

CVE-2026-64676 allows an untrusted host to tamper with confidential-guest memory through unauthorized mem-agent ttRPC methods.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203