HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-101919 — A flaw was found in the HyperShift operator. The operator copies user-provided K...

·Source: NIST NVD

Updated:

Executive Summary

A flaw was found in the HyperShift operator. The operator copies user-provided Kubernetes configuration (kubeconfig) secrets directly into the privileged control plane namespace without proper validation or sanitization. An authenticated user with cluster and secret creation permissions can exploit this vulnerability by supplying a configuration containing unauthorized executable plugins. When dow

Analysis

A flaw was found in the HyperShift operator. The operator copies user-provided Kubernetes configuration (kubeconfig) secrets directly into the privileged control plane namespace without proper validation or sanitization. An authenticated user with cluster and secret creation permissions can exploit this vulnerability by supplying a configuration containing unauthorized executable plugins. When downstream controllers consume this configuration, an attacker can achieve arbitrary code execution within the control plane. CVSS Score: 8.8. Published: 2026-10-05T18:17:30.907.

Indicators of Compromise (1)

CVE (1)
CVE-2026-101919
Source Attribution

Originally published by NIST NVD on Oct 5, 2026. Verified by: NIST.

Related Threats