Back to CVE List

CVE-2026-54099

HIGH SEVERITY

CVSS Score & Metrics

Base Score
8.8 / 10
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Vulnerability Description

A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-approver validates that a Certificate Signing Request contains the organization system:wicd-nodes but does not reject additional organization values such as system:masters. A compromised Windows worker node that holds WICD credentials can submit a CSR that is auto-approved and signed by the cluster, yielding a client certificate that grants cluster-administrator privileges and enabling full cluster takeover.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-269
Source
NVD
Vendor
Red Hat
Product
Red Hat OpenShift Container Platform 4, Red Hat OpenShift for Windows Containers

External References

Discussion (0)

Add Comment

No comments yet. Be the first!