PatchSiren cyber security CVE debrief
CVE-2026-54100 Red Hat CVE debrief
A flaw in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform allows an adjacent-network attacker to capture credentials and compromise Windows node identities by intercepting or redirecting WMCO's SSH session. This vulnerability enables attackers to gain unauthorized access to Windows nodes in the cluster, potentially leading to lateral movement and further exploitation. Defenders managing OpenShift Container Platform 4 clusters with Windows nodes using WMCO should assess exposure and apply remediation to prevent potential credential capture and node compromise.
- Vendor
- Red Hat
- Product
- Red Hat OpenShift Container Platform 4
- CVSS
- HIGH 8.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-22
- Original CVE updated
- 2026-09-09
- Advisory published
- 2026-06-22
- Advisory updated
- 2026-09-09
Who should care
Defenders managing OpenShift Container Platform 4 clusters with Windows nodes using WMCO should assess exposure and apply remediation. This includes verifying the exposure of Windows nodes, applying vendor remediation from Red Hat, and monitoring for suspicious SSH activity. Additionally, defenders should review and update WMCO configurations, perform a thorough review of the current security posture of Windows nodes in the cluster, and implement
Why it matters
CVE-2026-54100 allows an adjacent-network attacker to capture credentials and compromise Windows node identities in OpenShift Container Platform 4 clusters using WMCO. Defenders managing these clusters should verify exposure and apply vendor remediation.
- Credential capture and potential node compromise
- Exposure of Windows node identities in the cluster
- Possible lateral movement within the cluster
- Verification of WMCO configurations and node security
Technical summary
The Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform establishes SSH connections to Windows worker nodes without verifying the remote server host key. This allows an adjacent-network attacker who can intercept or redirect WMCO's SSH session to capture WICD and kubelet bootstrap credentials transferred during node configuration, potentially leading to compromise of Windows node identities in the cluster. The vulnerability highlights the importance of secure SSH connections and proper verification of remote server host keys in WMCO configurations.
Defensive priority
Defenders should prioritize verifying exposure of Windows nodes in OpenShift Container Platform 4 clusters using WMCO and applying vendor remediation.
Recommended defensive actions
- Verify exposure of Windows nodes in OpenShift Container Platform 4 clusters using WMCO
- Apply vendor remediation from Red Hat
- Monitor for suspicious SSH activity
- Review and update WMCO configurations
- Perform a thorough review of the current security posture of Windows nodes in the cluster
- Implement additional monitoring to detect potential lateral movement within the cluster
- Review and update incident response plans to address potential node compromise
Evidence notes
The CVE record and NVD entry provide details on the vulnerability in WMCO for Red Hat OpenShift Container Platform 4. The vulnerability is caused by WMCO establishing SSH connections to Windows worker nodes without verifying the remote server host key, allowing an adjacent-network attacker to intercept or redirect WMCO's SSH session and capture WICD and kubelet bootstrap credentials transferred during node configuration. Defenders should verify the exposure of Windows nodes in OpenShift Container Platform 4 clusters using WMCO and the
Sources and references
Verified primary and authoritative sources
-
CVE-2026-54100 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-54100
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-54100 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-54100
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:47173
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:61780
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-54100
[email protected] - Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54100.json
0b0ca135-0b70-47e7-9f44-1890c2a1c46c - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.