CVE-2026-101919

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in the HyperShift operator. The operator copies user-provided Kubernetes configuration (kubeconfig) secrets directly into the privileged control plane namespace without proper validation or sanitization. An authenticated user with cluster and secret creation permissions can exploit this vulnerability by supplying a configuration containing unauthorized executable plugins. When downstream controllers consume this configuration, an attacker can achieve arbitrary code execution within the control plane.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked 1d ago at 1 mentions (2026-10-05); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-10-05: 1Mentions · 2026-10-06: 110-0510-06
Referenced assets1 URL
Full discourse2 posts
  • ThreatAft@ThreatAft

    🔐 HyperShift Tenant Isolation Bypass — CVE-2026-101919 CVSS 8.8, Kubeconfig Passthrough Leads to Control Plane RCE Tenant isolation bypass via unsanitized kubeconfig passthrough 🔗 https://threataft.com/articles/hypershift-tenant-isolation-bypass-cve-2026-101919?utm_source=twitter&utm_medium=social&utm_campaign=share #CyberSecurity #ThreatIntel #HyperShift #OpenShift #Kubernetes

    0000028
    46 followersView on X
  • VulDB 🛡@vuldb

    We have just added an important vulnerability affecting Red Hat Multicluster Engine for Kubernetes (CVE-2026-101919) vuldb.​com/vuln/413675

    0000082
    2.3K followersView on X

Explore more