
There is a new vulnerability with elevated criticality in Red Hat OpenShift Data Foundation (CVE-2026-86330) https://vuldb.com/vuln/411051
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
An OS command injection flaw was found in the set_hostname_internal function of NooBaa's cluster_internal_api. This component is responsible for managing the Multi-Cloud Object Gateway in OpenShift Data Foundation. The vulnerability occurs because the hostname parameter is passed directly to a shell command without proper sanitization. An authenticated attacker with administrative privileges can provide a specially crafted hostname containing shell metacharacters to execute arbitrary commands on the host system with the privileges of the NooBaa process.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
NONE

There is a new vulnerability with elevated criticality in Red Hat OpenShift Data Foundation (CVE-2026-86330) https://vuldb.com/vuln/411051