CVE-2026-77176 is a security flaw identified in Kata Containers affecting configurations that use genpolicy for Confidential Containers guest protection. A malicious host operator can exploit insufficient validation of CreateContainer mount and storage rules to mount arbitrary container-rootfs paths over sensitive host locations. The vulnerability also allows provisioning of arbitrary content within the container environment. Successful exploitation could expose confidential information processed within the protected guest environment. It may also enable acceptance of attacker-controlled input, undermining the integrity of the confidential computing boundary. The flaw is particularly significant because it targets the trust boundary between host operators and confidential workloads. Red Hat has issued a security advisory, and a GitHub security advisory has been published by the Kata Containers project. The issue is tracked in Red Hat Bugzilla under bug ID 2517502.