CVE-2026-54100

Published Jun 22, 2026

Last updated 8 days ago

Overview

Description
A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishes SSH connections to Windows worker nodes without verifying the remote server host key. An adjacent-network attacker who can intercept or redirect WMCO's SSH session can capture WICD and kubelet bootstrap credentials transferred during node configuration, enabling compromise of Windows node identities in the cluster.
Source
secalert@redhat.com
NVD status
Analyzed
Products
openshift_container_platform, windows_machine_config_operator

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.3
Impact score
6
Exploitability score
1.6
Vector string
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity
HIGH

Weaknesses

secalert@redhat.com
CWE-295
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
CWE-295

Social media

Hype score
Not currently trending

Configurations