Database/Container, Kubernetes & orchestration
Kubernetes Image Builder: VM images built with the Proxmox provider ship default credentials
CVSS 9.8CVE-2024-9486Container, Kubernetes & orchestrationcurated
Impact
VM images built with the Proxmox provider ship default credentials; node takeover from the network
Who can reach it
Unauthenticated network reaching an affected node
What to do
Rebuild and redeploy every affected node image; this is a full fleet reimage, not a package update
References
Related entries
- Kubernetes Image Builder: Nutanix/OVA Windows images use default credentials unless overriddenCVE-2025-7342 · Kubernetes Image BuilderHigh
- Kubernetes Image Builder: Default credentials present during the build window for several providersCVE-2024-9594 · Kubernetes Image BuilderMedium
- ingress-nginx: "IngressNightmare": unauthenticated RCE in the admission controller, reachable from any podCVE-2025-1974 · ingress-nginxCritical
- Apache Camel K: YAML injection in custom resources creates arbitrary Kubernetes objects as the operatorCVE-2026-80352 · Apache Camel K operator (custom resource YAML handling)Critical
- JFrog Artifactory: unauthenticated network attacker can obtain administrative privilegesCVE-2026-82329 · JFrog Artifactory (authentication weakness under default configuration)Critical
- IBM Instana Agent Operator: a same-named CR in any namespace overwrites or deletes the shared ClusterRoleBindingCVE-2026-19274 · IBM Instana Agent Operator (cluster-scoped RBAC objects keyed by bare CR name)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.