<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>NooBaa - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/noobaa/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 28 Sep 2026 14:15:21 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/noobaa/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>OS Command Injection in NooBaa cluster_internal_api</title><link>https://feed.craftedsignal.io/briefs/2026-09-noobaa-cve/</link><pubDate>Mon, 28 Sep 2026 14:15:21 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-noobaa-cve/</guid><description>CVE-2026-86330 is an OS command injection vulnerability in the NooBaa cluster_internal_api component of Red Hat OpenShift Data Foundation, allowing authenticated administrative attackers to execute arbitrary system commands.</description><content:encoded><![CDATA[<p>CVE-2026-86330 is a high-severity OS command injection vulnerability identified in the set_hostname_internal function within the cluster_internal_api component of NooBaa. NooBaa serves as the Multi-Cloud Object Gateway for Red Hat OpenShift Data Foundation. The vulnerability stems from the direct and unsanitized passage of the hostname parameter into a shell execution context. This flaw permits an authenticated user possessing administrative privileges to inject shell metacharacters into the hostname field, resulting in the execution of arbitrary commands on the underlying host. The injected commands run with the privileges assigned to the NooBaa process, posing a significant risk to the integrity and confidentiality of the storage gateway environment.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows an authenticated administrative attacker to gain arbitrary code execution on the host system running the NooBaa component. This can lead to full compromise of the Multi-Cloud Object Gateway, unauthorized access to stored data, or lateral movement within the OpenShift environment. The vulnerability impacts deployments of Red Hat OpenShift Data Foundation utilizing the affected NooBaa version.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Detection engineering teams should monitor for suspicious process executions originating from the NooBaa process space.</p>
<ul>
<li>Audit administrative access to the cluster_internal_api to identify potential abuse of configuration parameters.</li>
<li>Apply security patches provided by Red Hat for OpenShift Data Foundation to address CVE-2026-86330.</li>
<li>Implement process-level monitoring on the NooBaa controller to detect unexpected shell invocations (e.g., /bin/sh or /bin/bash) triggered by the NooBaa process.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>remote-code-execution</category><category>openshift</category></item></channel></rss>