HyperShift CVE-2026-101919 — CVSS 8.8 Tenant Isolation Bypass via Kubeconfig Passthrough
An authenticated tenant with basic namespace permissions can break out to the host control plane in OpenShift clusters running Multicluster Engine with HyperShift. CVE-2026-101919 (CVSS 3.1 8.8, Red Hat: Important) is an improper input validation flaw in the hypershift-rhel9-operator. The ReconcileCredentials function copies a user-provided kubeconfig Secret verbatim into the privileged control plane namespace: // illustrative — simplified from source No exec-provider stripping, no AuthProvider validation, no InsecureSkipTLSVerify guard. A tenant embeds a malicious exec plugin in their kubecon
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in