Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
At this time, no mitigation or workaround is available for this vulnerability. Customers are advised to apply the appropriate updates as they become available.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 24 Jun 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat openshift Container Platform
Redhat openshift For Windows Containers |
|
| Vendors & Products |
Redhat openshift Container Platform
Redhat openshift For Windows Containers |
Tue, 23 Jun 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 22 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 22 Jun 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-approver validates that a Certificate Signing Request contains the organization system:wicd-nodes but does not reject additional organization values such as system:masters. A compromised Windows worker node that holds WICD credentials can submit a CSR that is auto-approved and signed by the cluster, yielding a client certificate that grants cluster-administrator privileges and enabling full cluster takeover. | |
| Title | Windows-machine-config-operator: windows-machine-config-operator: wicd csr extra-organization allows privilege escalation to system:masters | |
| First Time appeared |
Redhat
Redhat openshift Redhat windows Machine Config |
|
| Weaknesses | CWE-269 | |
| CPEs | cpe:/a:redhat:openshift:4 cpe:/a:redhat:windows_machine_config |
|
| Vendors & Products |
Redhat
Redhat openshift Redhat windows Machine Config |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-06-23T03:55:53.995Z
Reserved: 2026-06-11T19:02:42.736Z
Link: CVE-2026-54099
Updated: 2026-06-22T16:08:05.366Z
No data.
OpenCVE Enrichment
Updated: 2026-06-24T20:41:27Z