Skip to content
Threat Feed
high advisory

Arbitrary Code Execution in HyperShift Operator via Kubeconfig Injection

An authenticated user with secret creation permissions can exploit the HyperShift operator to execute arbitrary code in the control plane by injecting malicious plugins into kubeconfig secrets.

CVE search metadata

CVE search record: CVE-2026-101919. Severity: high. CVSS: 8.8. KEV: no. Product: HyperShift. Brief: Arbitrary Code Execution in HyperShift Operator via Kubeconfig Injection. Brief link: https://feed.craftedsignal.io/briefs/2026-10-hypershift-config-flaw/

The HyperShift operator, a component used in Red Hat OpenShift, contains a critical security vulnerability (CVE-2026-101919) arising from improper validation of user-supplied configurations. The operator processes user-provided Kubernetes configuration (kubeconfig) secrets and copies them directly into a privileged control plane namespace without performing sanitization. This flaw allows an authenticated user who possesses cluster and secret creation permissions to embed malicious executable plugins within a kubeconfig file. When the operator's downstream controllers automatically consume these injected secrets, the malicious plugins are executed within the context of the control plane, resulting in arbitrary code execution. This vulnerability presents a high risk to cluster environments where multi-tenancy or delegated secret management is utilized. Defenders must monitor for unauthorized or suspicious secret creation events and assess the configurations being processed by HyperShift controllers.

Impact

Successful exploitation allows an authenticated attacker to achieve arbitrary code execution within the control plane of a HyperShift-managed cluster. This bypasses typical isolation boundaries, potentially granting the attacker full control over the control plane, access to all cluster secrets, and the ability to manipulate workloads, lead to full cluster compromise.

Recommendation

Prioritized actions for detection engineering and security operations teams:

  • Audit all existing kubeconfig secrets within the namespace scope managed by the HyperShift operator for anomalous fields or suspicious plugin definitions.
  • Implement monitoring for excessive or unusual 'create' or 'update' operations on Kubernetes Secret objects performed by non-administrative service accounts.
  • Patch HyperShift deployments to the latest version provided by Red Hat as soon as the security update addressing CVE-2026-101919 is released.
  • Review RBAC policies to restrict which users or service accounts have the authority to create or modify Secret resources that are processed by the HyperShift operator.

Immediate actions

Review RBAC for secret creation permissions

IT Operations 48h

Mitigations

Upgrade HyperShift operator to the patched version when released by Red Hat

immediate IT Operations

CVE-2026-101919