High severity8.8NVD Advisory· Published Jun 22, 2026· Updated Jul 29, 2026
CVE-2026-54099
CVE-2026-54099
Description
A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-approver validates that a Certificate Signing Request contains the organization system:wicd-nodes but does not reject additional organization values such as system:masters. A compromised Windows worker node that holds WICD credentials can submit a CSR that is auto-approved and signed by the cluster, yielding a client certificate that grants cluster-administrator privileges and enabling full cluster takeover.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:redhat:openshift_container_platform:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:redhat:openshift_container_platform:*:*:*:*:*:*:*:*range: >=4.0,<4.22.1
- (no CPE)
cpe:2.3:a:redhat:windows_machine_config_operator:-:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:redhat:windows_machine_config_operator:-:*:*:*:*:*:*:*
- (no CPE)
Patches
Vulnerability mechanics
References
4- access.redhat.com/security/cve/CVE-2026-54099nvdVendor Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingVendor Advisory
- security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54099.jsonnvdVendor Advisory
- access.redhat.com/errata/RHSA-2026:47173nvd
News mentions
0No linked articles in our index yet.