PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-54099 Red Hat CVE debrief

A flaw in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform allows a compromised Windows worker node to potentially gain cluster-administrator privileges by exploiting the WICD CSR auto-approver's validation weakness, which could lead to unauthorized access and control of the cluster. Defenders responsible for securing Red Hat OpenShift Container Platform 4 environments, particularly those with Windows worker nodes, should assess exposure and prioritize mitigation. The vulnerability's high severity and potential impact on cluster security necessitate prompt verification and mitigation efforts.

Vendor
Red Hat
Product
Red Hat OpenShift Container Platform 4
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-22
Original CVE updated
2026-09-09
Advisory published
2026-06-22
Advisory updated
2026-09-09

Who should care

Defenders responsible for securing Red Hat OpenShift Container Platform 4 environments, particularly those with Windows worker nodes, should assess exposure and prioritize mitigation.

Why it matters

CVE-2026-54099 is a high-severity vulnerability in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform 4. A compromised Windows worker node could potentially exploit this flaw to gain cluster-administrator privileges, allowing for unauthorized access and control of the cluster. Defenders should prioritize verifying and mitigating this vulnerability, especially in environments with Windows worker nodes.

  • Potential privilege escalation to cluster-administrator privileges.
  • Possible unauthorized access to sensitive cluster resources.
  • Risk of lateral movement within the cluster.
  • Need for verification of Windows worker node integrity.

Technical summary

The Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform has a flaw in its WICD CSR auto-approver. The auto-approver validates that a Certificate Signing Request (CSR) contains the organization system:wicd-nodes but does not reject additional organization values such as system:masters. This allows a compromised Windows worker node that holds WICD credentials to submit a CSR that is auto-approved and signed by the cluster, potentially yielding a client certificate that grants cluster-administrator privileges.

Defensive priority

Defenders should prioritize verifying and mitigating the vulnerability on Windows worker nodes in OpenShift Container Platform 4 environments.

Recommended defensive actions

  • Verify the integrity of Windows worker nodes in OpenShift Container Platform 4 environments.
  • Apply patches or updates provided by Red Hat to address the vulnerability.
  • Monitor for suspicious Certificate Signing Requests (CSRs) and cluster activity.
  • Review and update access controls and permissions for cluster-administrator privileges.
  • Perform a thorough review of the cluster's configuration and security settings.
  • Implement additional monitoring and logging to detect potential security incidents.
  • Conduct a risk assessment to identify potential vulnerabilities and prioritize mitigation efforts.

Evidence notes

The CVE record and NVD detail page provide information on the vulnerability, including its description, CVSS score, and affected products. The Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform has a flaw in its WICD CSR auto-approver. The auto-approver validates that a Certificate Signing Request (CSR) contains the organization system:wicd-nodes but does not reject additional organization values such as system:masters. A compromised Windows worker node that holds WICD credentials can submit a CSR that is

Sources and references

Verified primary and authoritative sources

  • CVE-2026-54099 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-54099

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-54099 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-54099

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.