Vulnerability record · CVE-2026-54099 · published 22 June 2026
CVE-2026-54099: Redhat openshift container platform improper privilege management vulnerability
Redhat · Openshift Container Platform
A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-approver validates that a Certificate Signing Request contains the organization system:wicd-nodes but does not reject additional organization values such as system:masters. A compromised Windows worker node that holds WICD credentials can submit a CSR that is auto-approved and signed by the cluster, yielding a client certificate that grants cluster-administrator privileges and enabling full cluster takeover.
Description
A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-approver validates that a Certificate Signing Request contains the organization system:wicd-nodes but does not reject additional organization values such as system:masters. A compromised Windows worker node that holds WICD credentials can submit a CSR that is auto-approved and signed by the cluster, yielding a client certificate that grants cluster-administrator privileges and enabling full cluster takeover.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://access.redhat.com/errata/RHSA-2026:47173 | |
| https://access.redhat.com/errata/RHSA-2026:61780 | |
| https://access.redhat.com/security/cve/CVE-2026-54099 | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2487950 | Issue TrackingVendor Advisory |
| https://access.redhat.com/errata/RHSA-2026:47173 | |
| https://access.redhat.com/errata/RHSA-2026:61780 | |
| https://access.redhat.com/security/cve/CVE-2026-54099 | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2487950 | Issue TrackingVendor Advisory |
| https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54099.json | Vendor Advisory |
Track CVE-2026-54099 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-54099), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.