{
  "id": 12276738,
  "title": "HyperShift CVE-2026-101919 — CVSS 8.8 Tenant Isolation Bypass via Kubeconfig Passthrough",
  "url": "https://urgent.news/2026/10/06/hypershift-cve-2026-101919-cvss-8-8-tenant-isolation-bypass-via",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-06T01:55:30.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/threataft_dev/hypershift-cve-2026-101919-cvss-88-tenant-isolation-bypass-via-kubeconfig-passthrough-5p3"
  },
  "original_language": "en",
  "account": "OpenShift clusters running Multicluster Engine with HyperShift are vulnerable to an attacker breaking out of their tenant's namespace and gaining control of the entire control plane. CVE-2026-101919, rated CVSS 3.1 8.8 by Red Hat as Important, is caused by an improper input validation flaw in the hypershift-rhel9-operator. The ReconcileCredentials function simply copies a user-supplied kubeconfig Secret without any filtering or validation, allowing a malicious exec plugin to be embedded in the kubeconfig. When the operator copies this kubeconfig into the privileged control plane namespace, the downstream controller consumes the plugin and it executes with control plane privileges. This results in arbitrary code execution, access to all control plane secrets, and potential lateral movement across tenant boundaries, effectively defeating tenant isolation. There is no publicly available proof of concept, but a patch is available. To mitigate the risk, users should apply the HyperShift operator patch, restrict Secret creation to trusted accounts, deploy an admission webhook to block kubeconfig Secrets with exec plugins, and audit existing kubeconfig Secrets for embedded plugins.",
  "summary": "An authenticated tenant with basic namespace permissions can break out to the host control plane in OpenShift clusters running Multicluster Engine with HyperShift. CVE-2026-101919 (CVSS 3.1 8.8, Red Hat: Important) is an improper input validation flaw in the hypershift-rhel9-operator. The ReconcileCredentials function copies a user-provided kubeconfig Secret verbatim into the privileged control…",
  "key_points": [
    "OpenShift clusters with Multicluster Engine and HyperShift vulnerable to tenant isolation bypass.",
    "CVE-2026-101919 rated CVSS 3.1 8.8 by Red Hat as Important.",
    "Patch available; restrict Secret creation, deploy admission webhook, audit kubeconfig Secrets."
  ],
  "editors_take": "This vulnerability allows attackers to break out of their tenant namespace and gain control of the entire control plane, effectively defeating tenant isolation in OpenShift clusters running Multicluster Engine with HyperShift.",
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}