CyberRota
← Ana sayfaya dön

CVE-2026-54099

HIGH · CVSS 8.8 EPSS %0.07

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-06-22T14:17:40.820 · Çekilme zamanı: 2026-06-30T18:29:07.418185+00:00

CyberRota Yorumu

Detaylı analiz gerekiyor.

CVE
CVE-2026-54099
Severity
HIGH
CVSS
8.8
EPSS
%0.07
Windows

Orijinal NVD Açıklaması

A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-approver validates that a Certificate Signing Request contains the organization system:wicd-nodes but does not reject additional organization values such as system:masters. A compromised Windows worker node that holds WICD credentials can submit a CSR that is auto-approved and signed by the cluster, yielding a client certificate that grants cluster-administrator privileges and enabling full cluster takeover.