GPU VulnDB

Database/Control plane, storage & DevOps

Red Hat OpenShift Windows Machine Config Operator (unverified SSH host key): WMCO opens SSH to Windows worker nodes

CVE-2026-54100Control plane, storage & DevOpscurated

Impact

WMCO opens SSH to Windows worker nodes without verifying the host key, so an adjacent-network attacker intercepting the session captures WICD and kubelet bootstrap credentials - which is cluster-node identity, with scope change.

Who can reach it

Adjacent network position able to intercept or redirect WMCO's SSH session to a Windows node.

What to do

Apply RHSA-2026:47173. Operator update; afterwards rotate kubelet bootstrap credentials for Windows nodes, because captured bootstrap tokens remain valid until rotated.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.