Database/Control plane, storage & DevOps
Red Hat OpenShift Windows Machine Config Operator (unverified SSH host key): WMCO opens SSH to Windows worker nodes
CVSS 8.3CVE-2026-54100Control plane, storage & DevOpscurated
Impact
WMCO opens SSH to Windows worker nodes without verifying the host key, so an adjacent-network attacker intercepting the session captures WICD and kubelet bootstrap credentials - which is cluster-node identity, with scope change.
Who can reach it
Adjacent network position able to intercept or redirect WMCO's SSH session to a Windows node.
What to do
Apply RHSA-2026:47173. Operator update; afterwards rotate kubelet bootstrap credentials for Windows nodes, because captured bootstrap tokens remain valid until rotated.
References
Related entries
- Coder: workspace agent redirects let one tenant read, write and execute in another's workspaceCVE-2026-63443 · Coder (workspace agent API client, agentConn.apiClient redirect handling)High
- Renovate: mutual-TLS private key written to logs in cleartext when it appears outside its own fieldCVE-2026-88883 · Renovate self-hosted (log redaction of hostRules[].httpsPrivateKey)High
- IBM Spectrum Scale / Storage Scale core daemon (cluster RPC transport): An attacker who can speak to the cluster'sCVE-2020-4927 · IBM Spectrum Scale / Storage Scale core daemon (cluster RPC transport)High
- Ivanti Connect Secure: Web-component authentication bypass reaching restricted resourcesCVE-2023-46805 · Ivanti Connect SecureHigh
- Citrix NetScaler ADC/Gateway: Buffer overflow causing denial of service when configured as Gateway or AAA vserverCVE-2023-6549 · Citrix NetScaler ADC/GatewayHigh
- AmdCpmDisplayFeatureSMM - SMM callout (AMD-SB-7027): An SMM callout in the AmdCpmDisplayFeatureSMM driver lets ring-0CVE-2024-0179 · AmdCpmDisplayFeatureSMM - SMM callout (AMD-SB-7027)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.