OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-86330

HIGH · CVSS 7.2 EPSS 2.18%

Source: NVD + CISA KEV + EPSS · Published 2026-09-28 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

An OS command injection vulnerability exists in the set_hostname_internal function of NooBaa's cluster_internal_api, which is part of the Multi-Cloud Object Gateway in OpenShift Data Foundation. This flaw allows an authenticated attacker with administrative privileges to execute arbitrary commands on the host system by injecting shell metacharacters into the hostname parameter. Organizations using this component should prioritize remediation to prevent potential exploitation and safeguard their systems.

CVE
CVE-2026-86330
Severity
HIGH
CVSS
7.2
EPSS
2.18%

Original NVD Description

An OS command injection flaw was found in the set_hostname_internal function of NooBaa's cluster_internal_api. This component is responsible for managing the Multi-Cloud Object Gateway in OpenShift Data Foundation. The vulnerability occurs because the hostname parameter is passed directly to a shell command without proper sanitization. An authenticated attacker with administrative privileges can provide a specially crafted hostname containing shell metacharacters to execute arbitrary commands on the host system with the privileges of the NooBaa process.