Urgent.News

What's breaking now, across thousands of outlets.

Tech

HyperShift CVE-2026-101919 — CVSS 8.8 Tenant Isolation Bypass via Kubeconfig Passthrough

An authenticated tenant with basic namespace permissions can break out to the host control plane in OpenShift clusters running Multicluster Engine with HyperShift. CVE-2026-101919 (CVSS 3.1 8.8, Red Hat: Important) is an improper input validation flaw in the hypershift-rhel9-operator. The ReconcileCredentials function copies a user-provided kubeconfig Secret verbatim into the privileged control…

OpenShift clusters running Multicluster Engine with HyperShift are vulnerable to an attacker breaking out of their tenant's namespace and gaining control of the entire control plane. CVE-2026-101919, rated CVSS 3.1 8.8 by Red Hat as Important, is caused by an improper input validation flaw in the hypershift-rhel9-operator. The ReconcileCredentials function simply copies a user-supplied kubeconfig Secret without any filtering or validation, allowing a malicious exec plugin to be embedded in the kubeconfig.

When the operator copies this kubeconfig into the privileged control plane namespace, the downstream controller consumes the plugin and it executes with control plane privileges. This results in arbitrary code execution, access to all control plane secrets, and potential lateral movement across tenant boundaries, effectively defeating tenant isolation.

There is no publicly available proof of concept, but a patch is available. To mitigate the risk, users should apply the HyperShift operator patch, restrict Secret creation to trusted accounts, deploy an admission webhook to block kubeconfig Secrets with exec plugins, and audit existing kubeconfig Secrets for embedded plugins.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Node.js Feature Flag Rollouts: Stable Bucketing for 10% Notification Releases

Short answer: store the rollout percentage in the flag system, but make the release decision in the request path with a deterministic hash of an immutable user or account ID.

  • Store rollout percentage in flag system, decide release in request path
  • Use deterministic hash of immutable ID for consistent tenant delivery
  • Implement Go-based SHA-256 hashing to create 10,000 stable buckets

Phishing domains impersonate govt agencies

ISLAMABAD: The National Cyber Security Emergency Response Team (NCERT) has detected a number of suspected phishing domains created in the name of key national institutions, apparently aimed at…

Phishing domains impersonate govt agencies

ISLAMABAD: The National Cyber Security Emergency Response Team (NCERT) has detected a number of suspected phishing domains created in the name of key national institutions, apparently aimed at…

111 and 2049: RPC and NFS Endpoints in an Internet-Facing Population

111 and 2049: RPC and NFS Endpoints in an Internet-Facing Population Services that were never meant to leave the data centre Some protocols exist to make a private network work.

  • RPC and NFS endpoints found on internet-facing assets
  • Redis and memcached caches accept unauthenticated connections
  • Recommendation to verify reachability and enforce authentication

More from Tuesday 6 October →