OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-101919

HIGH · CVSS 8.8 EPSS 0.42% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-05 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The HyperShift operator in Kubernetes is vulnerable due to improper validation of user-provided kubeconfig secrets, allowing authenticated users with cluster and secret creation permissions to inject unauthorized executable plugins. This flaw can lead to arbitrary code execution within the privileged control plane, posing a significant risk to the integrity and security of the Kubernetes environment. Organizations using Kubernetes, particularly those leveraging the HyperShift operator, should prioritize addressing this vulnerability to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit arbitrary code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-101919
Severity
HIGH
CVSS
8.8
EPSS
0.42%
Kubernetes

Original NVD Description

A flaw was found in the HyperShift operator. The operator copies user-provided Kubernetes configuration (kubeconfig) secrets directly into the privileged control plane namespace without proper validation or sanitization. An authenticated user with cluster and secret creation permissions can exploit this vulnerability by supplying a configuration containing unauthorized executable plugins. When downstream controllers consume this configuration, an attacker can achieve arbitrary code execution within the control plane.