A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-approver validates that a Certificate Signing Request contains the organization system:wicd-nodes but does not reject additional organization values such as system:masters. A compromised Windows worker node that holds WICD credentials can submit a CSR that is auto-approved and signed by the cluster, yielding a client certificate that grants cluster-administrator privileges and enabling full cluster takeover.
Metrics
Affected Vendors & Products
References
History
Mon, 22 Jun 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-approver validates that a Certificate Signing Request contains the organization system:wicd-nodes but does not reject additional organization values such as system:masters. A compromised Windows worker node that holds WICD credentials can submit a CSR that is auto-approved and signed by the cluster, yielding a client certificate that grants cluster-administrator privileges and enabling full cluster takeover. | |
| Title | Windows-machine-config-operator: windows-machine-config-operator: wicd csr extra-organization allows privilege escalation to system:masters | |
| First Time appeared |
Redhat
Redhat openshift Redhat windows Machine Config |
|
| Weaknesses | CWE-269 | |
| CPEs | cpe:/a:redhat:openshift:4 cpe:/a:redhat:windows_machine_config |
|
| Vendors & Products |
Redhat
Redhat openshift Redhat windows Machine Config |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-06-22T12:46:04.051Z
Reserved: 2026-06-11T19:02:42.736Z
Link: CVE-2026-54099
No data.
No data.
No data.
OpenCVE Enrichment
No data.