CVE-2026-54099
A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.11%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-approver validates that a Certificate Signing Request contains the organization system:wicd-nodes but does not reject additional organization values such as system:masters. A compromised Windows worker node that holds WICD credentials can submit a CSR that is auto-approved and signed by the cluster, yielding a client certificate that grants cluster-administrator privileges and enabling full cluster takeover.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- EPSS
- 0.11% probability · 1th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-269
- Affected
- redhat/openshift container platform · redhat/windows machine config operator
- Source
- secalert@redhat.com
References
- https://access.redhat.com/errata/RHSA-2026:47173
- https://access.redhat.com/errata/RHSA-2026:61780
- https://access.redhat.com/security/cve/CVE-2026-54099Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2487950Issue Tracking, Vendor Advisory
- https://access.redhat.com/errata/RHSA-2026:47173
- https://access.redhat.com/errata/RHSA-2026:61780
- https://access.redhat.com/security/cve/CVE-2026-54099Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2487950Issue Tracking, Vendor Advisory
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54099.jsonVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.