PatchSiren cyber security CVE debrief
CVE-2026-54099 Red Hat CVE debrief
A flaw in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform allows a compromised Windows worker node to potentially gain cluster-administrator privileges by exploiting the WICD CSR auto-approver's validation weakness, which could lead to unauthorized access and control of the cluster. Defenders responsible for securing Red Hat OpenShift Container Platform 4 environments, particularly those with Windows worker nodes, should assess exposure and prioritize mitigation. The vulnerability's high severity and potential impact on cluster security necessitate prompt verification and mitigation efforts.
- Vendor
- Red Hat
- Product
- Red Hat OpenShift Container Platform 4
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-22
- Original CVE updated
- 2026-09-09
- Advisory published
- 2026-06-22
- Advisory updated
- 2026-09-09
Who should care
Defenders responsible for securing Red Hat OpenShift Container Platform 4 environments, particularly those with Windows worker nodes, should assess exposure and prioritize mitigation.
Why it matters
CVE-2026-54099 is a high-severity vulnerability in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform 4. A compromised Windows worker node could potentially exploit this flaw to gain cluster-administrator privileges, allowing for unauthorized access and control of the cluster. Defenders should prioritize verifying and mitigating this vulnerability, especially in environments with Windows worker nodes.
- Potential privilege escalation to cluster-administrator privileges.
- Possible unauthorized access to sensitive cluster resources.
- Risk of lateral movement within the cluster.
- Need for verification of Windows worker node integrity.
Technical summary
The Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform has a flaw in its WICD CSR auto-approver. The auto-approver validates that a Certificate Signing Request (CSR) contains the organization system:wicd-nodes but does not reject additional organization values such as system:masters. This allows a compromised Windows worker node that holds WICD credentials to submit a CSR that is auto-approved and signed by the cluster, potentially yielding a client certificate that grants cluster-administrator privileges.
Defensive priority
Defenders should prioritize verifying and mitigating the vulnerability on Windows worker nodes in OpenShift Container Platform 4 environments.
Recommended defensive actions
- Verify the integrity of Windows worker nodes in OpenShift Container Platform 4 environments.
- Apply patches or updates provided by Red Hat to address the vulnerability.
- Monitor for suspicious Certificate Signing Requests (CSRs) and cluster activity.
- Review and update access controls and permissions for cluster-administrator privileges.
- Perform a thorough review of the cluster's configuration and security settings.
- Implement additional monitoring and logging to detect potential security incidents.
- Conduct a risk assessment to identify potential vulnerabilities and prioritize mitigation efforts.
Evidence notes
The CVE record and NVD detail page provide information on the vulnerability, including its description, CVSS score, and affected products. The Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform has a flaw in its WICD CSR auto-approver. The auto-approver validates that a Certificate Signing Request (CSR) contains the organization system:wicd-nodes but does not reject additional organization values such as system:masters. A compromised Windows worker node that holds WICD credentials can submit a CSR that is
Sources and references
Verified primary and authoritative sources
-
CVE-2026-54099 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-54099
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-54099 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-54099
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:47173
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:61780
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-54099
[email protected] - Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54099.json
0b0ca135-0b70-47e7-9f44-1890c2a1c46c - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.