PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-54100 Red Hat CVE debrief

A flaw in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform allows an adjacent-network attacker to capture credentials and compromise Windows node identities by intercepting or redirecting WMCO's SSH session. This vulnerability enables attackers to gain unauthorized access to Windows nodes in the cluster, potentially leading to lateral movement and further exploitation. Defenders managing OpenShift Container Platform 4 clusters with Windows nodes using WMCO should assess exposure and apply remediation to prevent potential credential capture and node compromise.

Vendor
Red Hat
Product
Red Hat OpenShift Container Platform 4
CVSS
HIGH 8.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-22
Original CVE updated
2026-09-09
Advisory published
2026-06-22
Advisory updated
2026-09-09

Who should care

Defenders managing OpenShift Container Platform 4 clusters with Windows nodes using WMCO should assess exposure and apply remediation. This includes verifying the exposure of Windows nodes, applying vendor remediation from Red Hat, and monitoring for suspicious SSH activity. Additionally, defenders should review and update WMCO configurations, perform a thorough review of the current security posture of Windows nodes in the cluster, and implement

Why it matters

CVE-2026-54100 allows an adjacent-network attacker to capture credentials and compromise Windows node identities in OpenShift Container Platform 4 clusters using WMCO. Defenders managing these clusters should verify exposure and apply vendor remediation.

  • Credential capture and potential node compromise
  • Exposure of Windows node identities in the cluster
  • Possible lateral movement within the cluster
  • Verification of WMCO configurations and node security

Technical summary

The Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform establishes SSH connections to Windows worker nodes without verifying the remote server host key. This allows an adjacent-network attacker who can intercept or redirect WMCO's SSH session to capture WICD and kubelet bootstrap credentials transferred during node configuration, potentially leading to compromise of Windows node identities in the cluster. The vulnerability highlights the importance of secure SSH connections and proper verification of remote server host keys in WMCO configurations.

Defensive priority

Defenders should prioritize verifying exposure of Windows nodes in OpenShift Container Platform 4 clusters using WMCO and applying vendor remediation.

Recommended defensive actions

  • Verify exposure of Windows nodes in OpenShift Container Platform 4 clusters using WMCO
  • Apply vendor remediation from Red Hat
  • Monitor for suspicious SSH activity
  • Review and update WMCO configurations
  • Perform a thorough review of the current security posture of Windows nodes in the cluster
  • Implement additional monitoring to detect potential lateral movement within the cluster
  • Review and update incident response plans to address potential node compromise

Evidence notes

The CVE record and NVD entry provide details on the vulnerability in WMCO for Red Hat OpenShift Container Platform 4. The vulnerability is caused by WMCO establishing SSH connections to Windows worker nodes without verifying the remote server host key, allowing an adjacent-network attacker to intercept or redirect WMCO's SSH session and capture WICD and kubelet bootstrap credentials transferred during node configuration. Defenders should verify the exposure of Windows nodes in OpenShift Container Platform 4 clusters using WMCO and the

Sources and references

Verified primary and authoritative sources

  • CVE-2026-54100 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-54100

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-54100 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-54100

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.