CVE WATCH / VULNERABILITY DETAIL

CVE-2026-101919

HIGHCVSS 8.8NVD feed

Published 5 October 2026 · tracked since 6 October 2026

Description

A flaw was found in the HyperShift operator. The operator copies user-provided Kubernetes configuration (kubeconfig) secrets directly into the privileged control plane namespace without proper validation or sanitization. An authenticated user with cluster and secret creation permissions can exploit

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-101919 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-101919

HIGHCVSS 8.8NVD feed

Published 5 October 2026 · tracked since 6 October 2026

Description

A flaw was found in the HyperShift operator. The operator copies user-provided Kubernetes configuration (kubeconfig) secrets directly into the privileged control plane namespace without proper validation or sanitization. An authenticated user with cluster and secret creation permissions can exploit

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]