CVE-2026-54099 Details
Description
A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-approver validates that a Certificate Signing Request contains the organization system:wicd-nodes but does not reject additional organization values such as system:masters. A compromised Windows worker node that holds WICD credentials can submit a CSR that is auto-approved and signed by the cluster, yielding a client certificate that grants cluster-administrator privileges and enabling full cluster takeover.
A vulnerability exists in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD Certificate Signing Request (CSR) auto-approver improperly validates organization values, allowing a compromised Windows worker node with WICD credentials to submit a CSR that is auto-approved and signed by the cluster. This results in a client certificate that grants cluster-administrator privileges, enabling full control over the cluster.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2026:47173 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:61780 | redhat-SADP | |
| https://access.redhat.com/security/cve/CVE-2026-54099 | redhat-SADP | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2487950 | redhat-SADP | Issue TrackingVendor Advisory |
| https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54099.json | redhat-SADP | Vendor Advisory |
| https://access.redhat.com/errata/RHSA-2026:47173 | [email protected] | |
| https://access.redhat.com/errata/RHSA-2026:61780 | [email protected] | |
| https://access.redhat.com/security/cve/CVE-2026-54099 | [email protected] | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2487950 | [email protected] | Issue TrackingVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-269 | Improper Privilege Management | redhat-SADP |
| CWE-269 | Improper Privilege Management | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| redhat openshift container platform | >= 4.0, < 4.22.1 |
CPE
Remediation
| |
| redhat windows machine config operator | All versions |
CPE
Remediation
| |
Change History
15 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 9, 2026 | CVE Modified | redhat-SADP |
| Sep 7, 2026 | CVE Modified | redhat-SADP |
| Sep 6, 2026 | CVE Modified | [email protected] |
| Sep 5, 2026 | CVE Modified | [email protected] |
| Sep 1, 2026 | CVE Modified | redhat-SADP |
| Sep 1, 2026 | CVE Modified | [email protected] |
| Sep 1, 2026 | CVE Modified | redhat-SADP |
| Jul 29, 2026 | CVE Modified | redhat-SADP |
| Jul 28, 2026 | CVE Modified | [email protected] |
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jul 8, 2026 | Initial Analysis | [email protected] |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 23, 2026 | CVE Modified | CISA-ADP |
| Jun 22, 2026 | CVE Modified | CISA-ADP |
| Jun 22, 2026 | New CVE Received | [email protected] |