Database/Control plane, storage & DevOps
KubeEdge (ConfigUpdateJob handler, updateFields): REMOTE CODE EXECUTION ON EDGE NODES via a normal Kubernetes API
Impact
REMOTE CODE EXECUTION ON EDGE NODES via a normal Kubernetes API object. The ConfigUpdateJob handler concatenated caller-supplied updateFields values into a command string and ran it through a system shell, so shell metacharacters in a configuration field execute as commands on every targeted node with the privileges of the KubeEdge process. For anyone running distributed inference on edge or far-edge GPU boxes, the practical picture is that a namespaced RBAC grant intended to let a team push configuration turns into node-level execution across the fleet — and the fleet is the part of the estate with the least physical oversight and the weakest chance of anyone noticing.
Who can reach it
Network, authenticated: the attacker needs RBAC permission to create or update ConfigUpdateJob resources and an enrolled target edge node. No user interaction beyond the job being processed.
What to do
Upgrade to KubeEdge 1.23.1, 1.22.2 or 1.21.2, where keadm config-update is invoked with structured arguments and the whole --set value is passed as a single literal. Before that lands, restrict RBAC on ConfigUpdateJob to trusted administrators, avoid ConfigUpdateJob where the input cannot be fully trusted, and monitor edge-node process activity for unexpected commands.
References
Related entries
- KubeEdge (NodeUpgradeJob handler, v1alpha2 API): REMOTE CODE EXECUTION ON EDGE NODES through the upgrade path. TheNCVD-2026-052-kubeedge-nodeupgradejob-handler · KubeEdge (NodeUpgradeJob handler, v1alpha2 API)High
- APC Network Management Card 4 (NMC4): An unauthenticated attacker can manipulate URL parameters to walk out of the webCVE-2024-58310 · APC Network Management Card 4 (NMC4)High
- Cisco Nexus Dashboard Fabric Controller (SSH host key validation): NDFC does not validate the SSH host keysCVE-2025-20163 · Cisco Nexus Dashboard Fabric Controller (SSH host key validation)High
- MinIO (S3 API, unsigned-trailer uploads): Signature validation on unsigned-trailer uploads is incomplete, so knowingCVE-2025-31489 · MinIO (S3 API, unsigned-trailer uploads)High
- HPE OneView for VMware vCenter (vertical privilege escalation): A read-only user performs administrative actionsCVE-2025-37101 · HPE OneView for VMware vCenter (vertical privilege escalation)High
- F5 BIG-IP (iHealth command / tmsh restricted shell): An authenticated attacker with at least a resource-administratorCVE-2025-61958 · F5 BIG-IP (iHealth command / tmsh restricted shell)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.