CVE-2026-54099
Red Hat Red Hat OpenShift for Windows Containers 10.22, Red Hat OpenShift Container Platform 4, openshift container platform 취약점
A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-approver validates that a Certificate Signing Request contains the organization system:wicd-nodes but does not reject additional organization values such as system:masters. A compromised Windows worker node that holds WICD credentials can submit a CSR that is auto-approved and signed by the cluster, yielding a client certificate that grants cluster-administrator privileges and enabling full cluster takeover.
- 대응 우선순위
- 점검
- CVSS
- 8.8
- EPSS
- 0.10% 백분위 1.27% · 2026.07.28 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.06.22