← Vulnerability feed

Vulnerability record · CVE-2025-57854 · published 8 April 2026

CVE-2025-57854: Redhat openshift update service incorrect default permissions vulnerability

Redhat · Openshift Update Service

A container privilege escalation flaw was found in certain OpenShift Update Service (OSUS) images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands within an affected container, even as a non-root user, may be able to leverage their membership in the root group to modify the /etc/passwd file. This could allow the attacker to add a new user with any arbitrary UID, including UID 0, leading to full root privileges within the container.

6.4 CVSS 3.1 Medium EPSS 0.15% · top 96.8% CWE-276 · Incorrect default permissions
6.4CVSS 3.1 base score
0.15%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
24 Jul 2026Last modified by NVD

Description

A container privilege escalation flaw was found in certain OpenShift Update Service (OSUS) images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands within an affected container, even as a non-root user, may be able to leverage their membership in the root group to modify the /etc/passwd file. This could allow the attacker to add a new user with any arbitrary UID, including UID 0, leading to full root privileges within the container.

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-57854 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.2CVE-2026-74243Redhat openshift update service missing authentication for critical function vulnerabilityA flaw was found in Red Hat Quay. When the SECURITY_SCANNER_V4_PSK (pre-shared key) is not set, a remote unauthenticated attacker can send POST reque…EPSS 0.46%7.5CVE-2026-74244Redhat openshift update service improper verification of cryptographic signature vulnerabilityA flaw was found in Red Hat Quay's Stripe billing webhook handler. This vulnerability allows an unauthenticated attacker to forge billing events by s…EPSS 0.23%7.5CVE-2026-74245Redhat openshift update service missing authentication for critical function vulnerabilityA flaw was found in Red Hat Quay's exported logs feature. An unauthenticated attacker with a valid file ID could download exported action logs withou…EPSS 0.42%7.1CVE-2026-74247Redhat openshift update service server-side request forgery (ssrf) vulnerabilityA flaw was found in Red Hat Quay. A user with FEATURE_BUILD_SUPPORT enabled and repository write access can exploit a Server-Side Request Forgery (SS…EPSS 0.25%6.5CVE-2026-74241Redhat openshift update service ldap injection vulnerabilityA flaw was found in Red Hat Quay's external Lightweight Directory Access Protocol (LDAP) authentication handling. When an LDAP referral is returned d…EPSS 0.31%5.4CVE-2026-74240Redhat openshift update service improper authentication vulnerabilityA flaw was found in Red Hat Quay's JWT (JSON Web Token) validation for federated robot accounts and single sign-on (SSO) authentication. Multiple iss…EPSS 0.29%4.4CVE-2026-74242Redhat openshift update service insecure direct object reference vulnerabilityA flaw was found in Red Hat Quay. An administrator of any repository, by knowing or guessing a target notification's Universally Unique Identifier (U…EPSS 0.33%7.8CVE-2026-87886Acronis Backup plugins for cPanel, Plesk and DirectAdmin local privilege escalationAcronis Backup plugins for cPanel & WHM, Plesk and DirectAdmin on Linux ship with insecure file permissions (CWE-276), allowing a local user to escal…KEVEPSS 0.23%analysed

Source: NIST National Vulnerability Database (record CVE-2025-57854), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.