Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-54099

Опубликовано: 10 июн. 2026
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-approver validates that a Certificate Signing Request contains the organization system:wicd-nodes but does not reject additional organization values such as system:masters. A compromised Windows worker node that holds WICD credentials can submit a CSR that is auto-approved and signed by the cluster, yielding a client certificate that grants cluster-administrator privileges and enabling full cluster takeover.

Отчет

This flaw affects OpenShift clusters running the Windows Machine Config Operator (WMCO) with one or more Windows worker nodes. Clusters without Windows nodes or without WMCO are not affected. Exploitation requires compromising a Windows worker node and obtaining WICD credentials from that node. Red Hat Security Ratings classify this as Important because a successful attack grants cluster-administrator access from a compromised Windows node.

Меры по смягчению последствий

At this time, no mitigation or workaround is available for this vulnerability. Customers are advised to apply the appropriate updates as they become available.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 4openshift4-wincw/windows-machine-config-rhel8-operatorAffected
Red Hat OpenShift Container Platform 4openshift4-wincw/windows-machine-config-rhel9-operatorAffected
Red Hat OpenShift for Windows Containersopenshift4-wincw/windows-machine-config-rhel9-operatorAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-269
https://bugzilla.redhat.com/show_bug.cgi?id=2487950windows-machine-config-operator: windows-machine-config-operator: WICD CSR extra-Organization allows privilege escalation to system:masters

EPSS

Процентиль: 0%
0.00073
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
около 1 месяца назад

A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-approver validates that a Certificate Signing Request contains the organization system:wicd-nodes but does not reject additional organization values such as system:masters. A compromised Windows worker node that holds WICD credentials can submit a CSR that is auto-approved and signed by the cluster, yielding a client certificate that grants cluster-administrator privileges and enabling full cluster takeover.

CVSS3: 8.8
github
около 1 месяца назад

A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-approver validates that a Certificate Signing Request contains the organization system:wicd-nodes but does not reject additional organization values such as system:masters. A compromised Windows worker node that holds WICD credentials can submit a CSR that is auto-approved and signed by the cluster, yielding a client certificate that grants cluster-administrator privileges and enabling full cluster takeover.

EPSS

Процентиль: 0%
0.00073
Низкий

8.8 High

CVSS3