CVE-2026-29955Disclosure(cloudark / kubeplus)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The `/registercrd` endpoint in KubePlus 4.14 in the kubeconfiggenerator component is vulnerable to command injection. The component uses `subprocess.Popen()` with `shell=True` parameter to execute shell commands, and the user-supplied `chartName` parameter is directly concatenated into the command string without any sanitization or validation. An attacker can inject arbitrary shell commands by crafting a malicious `chartName` parameter value.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • kubeplus

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-19); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
kubeplus

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-19: 1Mentions · 2026-09-14: 1Technical Details · 2026-04-19: 104-1909-14
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-04-191
Disclosure1
2026-09-141
General1
Full discourse2 posts
  • KickingSassTakingAim@KiknSassTaknAim
    General

    Instead, "29955" most commonly refers to: H&R 29955 Sport Springs: A specific automotive aftermarket performance part. A Local ZIP Code / Postal Code: For example, the population of the Swiss municipality Yverdon-les-Bains is famously noted at 29,955. CVE-2026-29955: A cyber security vulnerability record ●Interestingly 29955 ALSO alphanumeric to: BIIEE An Automotive company in China Changsha, Hunan Or.. phonetically BYE!

    Post summary

    Text merely notes CVE-2026-29955 as one of several possible interpretations for '29955' without providing vulnerability specifics, PoC, exploit details, or remediation.

    1001081
    228 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-29955 The `/registercrd` endpoint in KubePlus 4.14 in the kubeconfiggenerator component is vulnerable to command injection. The component uses `subprocess.Popen()` with `sh… https://www.cve.org/CVERecord?id=CVE-2026-29955

    Post summary

    The statement announces that CVE-2026-29955 causes command injection in the /registercrd endpoint of KubePlus 4.14, providing technical details but no PoC, exploit, or mitigation.

    00000151
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcloudarkkubeplus---

Explore more