{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aredhatnoobaa/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:redhat:openshift_data_foundation:*:*:*:*:*:*:*:*","cpe:2.3:a:redhat:noobaa:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-86330"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["OpenShift Data Foundation","NooBaa"],"_cs_severities":["high"],"_cs_tags":["vulnerability","remote-code-execution","openshift"],"_cs_type":"advisory","_cs_vendors":["Red Hat"],"content_html":"\u003cp\u003eCVE-2026-86330 is a high-severity OS command injection vulnerability identified in the set_hostname_internal function within the cluster_internal_api component of NooBaa. NooBaa serves as the Multi-Cloud Object Gateway for Red Hat OpenShift Data Foundation. The vulnerability stems from the direct and unsanitized passage of the hostname parameter into a shell execution context. This flaw permits an authenticated user possessing administrative privileges to inject shell metacharacters into the hostname field, resulting in the execution of arbitrary commands on the underlying host. The injected commands run with the privileges assigned to the NooBaa process, posing a significant risk to the integrity and confidentiality of the storage gateway environment.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows an authenticated administrative attacker to gain arbitrary code execution on the host system running the NooBaa component. This can lead to full compromise of the Multi-Cloud Object Gateway, unauthorized access to stored data, or lateral movement within the OpenShift environment. The vulnerability impacts deployments of Red Hat OpenShift Data Foundation utilizing the affected NooBaa version.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eDetection engineering teams should monitor for suspicious process executions originating from the NooBaa process space.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAudit administrative access to the cluster_internal_api to identify potential abuse of configuration parameters.\u003c/li\u003e\n\u003cli\u003eApply security patches provided by Red Hat for OpenShift Data Foundation to address CVE-2026-86330.\u003c/li\u003e\n\u003cli\u003eImplement process-level monitoring on the NooBaa controller to detect unexpected shell invocations (e.g., /bin/sh or /bin/bash) triggered by the NooBaa process.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-28T14:15:21Z","date_published":"2026-09-28T14:15:21Z","id":"https://feed.craftedsignal.io/briefs/2026-09-noobaa-cve/","summary":"CVE-2026-86330 is an OS command injection vulnerability in the NooBaa cluster_internal_api component of Red Hat OpenShift Data Foundation, allowing authenticated administrative attackers to execute arbitrary system commands.","title":"OS Command Injection in NooBaa cluster_internal_api","url":"https://feed.craftedsignal.io/briefs/2026-09-noobaa-cve/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:redhat:noobaa:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}