
Windows-machine-config-operator: wicd csr extra-organization allows privilege escalation to system:masters CVE: CVE-2026-54099 Vendor: Red hat Product: Red Hat OpenShift Container Platform 4 CVSS: 8.8 Credits: n/a Description: A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-approver validates that a Certificate Signing Request contains the organization system:wicd-nodes but does not reject additional organization values such as system:masters. A compromised Windows worker node that holds WICD credentials can submit a CSR that is auto-approved and signed by the cluster, yielding a client certificate that grants cluster-administrator privileges and enabling full cluster takeover. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-54099 • https://access.redhat.com/security/cve/CVE-2026-54099 • https://bugzilla.redhat.com/show_bug.cgi?id=2487950 #dbugs_vuln
Post summary
The statement reports a privilege‑escalation flaw in Red Hat OpenShift’s Windows Machine Config Operator that lets a node obtain cluster‑admin certificates via auto‑approved CSRs (CVSS 8.8); no PoC, exploit, or patch is provided.



