CVE-2026-54100Disclosure(redhat / openshift_container_platform)

LOWCVSS 8.3 · HIGH

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishes SSH connections to Windows worker nodes without verifying the remote server host key. An adjacent-network attacker who can intercept or redirect WMCO's SSH session can capture WICD and kubelet bootstrap credentials transferred during node configuration, enabling compromise of Windows node identities in the cluster.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-295

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openshift_container_platform
  • windows_machine_config_operator

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • 4 total mentions across 1 day

Affected systems

Vendors
Products
openshift_container_platformwindows_machine_config_operator

1 version affected across 2 products

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-06-22: 4Technical Details · 2026-06-22: 206-22
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets6 URLs
Full discourse4 posts
  • dbugs@ptdbugs
    Disclosure

    Windows-machine-config-operator: ssh host key not verified enables credential theft CVE: CVE-2026-54100 Vendor: Red hat Product: Red Hat OpenShift Container Platform 4 CVSS: 8.3 Credits: n/a Description: A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishes SSH connections to Windows worker nodes without verifying the remote server host key. An adjacent-network attacker who can intercept or redirect WMCO's SSH session can capture WICD and kubelet bootstrap credentials transferred during node configuration, enabling compromise of Windows node identities in the cluster. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-54100 • https://access.redhat.com/security/cve/CVE-2026-54100 • https://bugzilla.redhat.com/show_bug.cgi?id=2487953 #dbugs_vuln

    Post summary

    Red Hat OpenShift Container Platform’s Windows Machine Config Operator flaw allows an adjacent‑network attacker to intercept SSH sessions and capture bootstrap credentials, with a CVSS 8.3 rating.

    01060617
    3.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-54100 Unverified SSH Host Key in Red Hat OpenShift Windows Machine Config Operator https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-54100

    Post summary

    The text merely lists the CVE identifier and a brief description, with no evidence of PoC, exploitation, or mitigation details.

    00000125
    4.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-54100 A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishes SSH connections to Windows worker nodes with… https://www.cve.org/CVERecord?id=CVE-2026-54100 ----- Traducción: Se encontró una vu… http://infoflow.cloud`

    Post summary

    A brief notice announcing CVE-2026-54100, a flaw in the Windows Machine Config Operator for Red Hat OpenShift, with no further technical or exploitation details.

    0000036
    88 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-54100 A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishes SSH connections to Windows worker nodes with… https://www.cve.org/CVERecord?id=CVE-2026-54100

    Post summary

    The text announces a newly disclosed flaw in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform, noting its relation to SSH connections to Windows worker nodes.

    00000701
    57.7K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appredhatopenshift_container_platform---
Appredhatwindows_machine_config_operator---

Explore more