Description
A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishes SSH connections to Windows worker nodes without verifying the remote server host key. An adjacent-network attacker who can intercept or redirect WMCO's SSH session can capture WICD and kubelet bootstrap credentials transferred during node configuration, enabling compromise of Windows node identities in the cluster.
Published: 2026-06-22
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Workaround

At this time, no mitigation or workaround is available for this vulnerability. Customers are advised to apply the appropriate updates as they become available.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 24 Jun 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat openshift Container Platform
Redhat openshift For Windows Containers
Vendors & Products Redhat openshift Container Platform
Redhat openshift For Windows Containers

Tue, 23 Jun 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Mon, 22 Jun 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 22 Jun 2026 13:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishes SSH connections to Windows worker nodes without verifying the remote server host key. An adjacent-network attacker who can intercept or redirect WMCO's SSH session can capture WICD and kubelet bootstrap credentials transferred during node configuration, enabling compromise of Windows node identities in the cluster.
Title Windows-machine-config-operator: windows-machine-config-operator: ssh host key not verified enables credential theft
First Time appeared Redhat
Redhat openshift
Redhat windows Machine Config
Weaknesses CWE-295
CPEs cpe:/a:redhat:openshift:4
cpe:/a:redhat:windows_machine_config
Vendors & Products Redhat
Redhat openshift
Redhat windows Machine Config
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Redhat Openshift Openshift Container Platform Openshift For Windows Containers Windows Machine Config
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-06-23T03:55:55.139Z

Reserved: 2026-06-11T19:02:42.736Z

Link: CVE-2026-54100

cve-icon Vulnrichment

Updated: 2026-06-22T14:11:35.409Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Important

Publid Date: 2026-06-10T00:00:00Z

Links: CVE-2026-54100 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-06-24T20:41:26Z

Weaknesses