OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-62371

HIGH · CVSS 8.8 EPSS 0.48% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-21 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

The KubeEdge NodeUpgradeJob handler is vulnerable to command injection due to improper handling of user-controlled input in the spec.version and spec.image fields, allowing an authenticated user to execute arbitrary commands on edge nodes. This vulnerability can lead to a compromise of node confidentiality, integrity, and availability, making it critical for organizations using KubeEdge versions 1.12.0 through 1.23.1 to prioritize upgrading to the patched versions 1.21.2, 1.22.2, or 1.23.1. Users with permissions to create or update NodeUpgradeJob resources should be particularly vigilant.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-62371
Severity
HIGH
CVSS
8.8
EPSS
0.48%

Original NVD Description

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.12.0 until 1.21.2, 1.22.2, and 1.23.1, the v1alpha2 NodeUpgradeJob handler in edge/pkg/taskmanager/actions/nodeupgradejob.go concatenates authenticated user-controlled spec.version and spec.image values into the keadm upgrade edge shell command. A user with permission to create or update NodeUpgradeJob resources can supply shell metacharacters in either field, causing arbitrary commands to execute on targeted edge nodes with the privileges of the upgrade process and compromising node confidentiality, integrity, and availability. This issue is fixed in versions 1.21.2, 1.22.2, and 1.23.1.