CVE 2026 86330
An OS command injection flaw was found in the set_hostname_internal function of NooBaa's cluster_internal_api. This component is responsible for managing the Multi-Cloud Object Gateway in OpenShift Data Foundation. The vulnerability occurs because the hostname parameter is passed directly to a shell command without proper sanitization. An authenticated attacker with administrative privileges can provide a specially crafted hostname containing shell metacharacters to execute arbitrary commands on the host system with the privileges of the NooBaa process.
The Red Hat Product Security team has assessed the severity of this vulnerability as Important, given that exploitation requires administrative privileges. Successful exploitation allows an attacker to execute arbitrary OS commands on the NooBaa container. The vulnerability's root cause is the improper neutralization of special elements used in an OS command (Command Injection).
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Bugzilla 2529295 : noobaa-core: noobaa-core: OS command injection in cluster_internal_api.set_hostname_internal
CWE-78 : Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Common Vulnerability Scoring System (CVSS) Score Details
Info alert: Important note
CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications ).
The following CVSS metrics and score provided are preliminary and subject to review.
CVSS v3 Score Breakdown
Red Hat: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
cve.org: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Understanding the Weakness (CWE)
Confidentiality,Integrity,Availability,Non-Repudiation
Technical Impact: Execute Unauthorized Code or Commands; DoS: Crash, Exit, or Restart; Read Files or Directories; Modify Files or Directories; Read Application Data; Modify Application Data; Hide Activities
Attackers could execute unauthorized operating system commands, which could then be used to disable the product, or read and modify data for which the attacker does not have permissions to access directly. Since the targeted application is directly executing the commands instead of the attacker, any malicious activities may appear to come from the application or the application's owner.
Red Hat would like to thank Antoine ARDINO (Elweth) for reporting this issue.
Frequently Asked Questions
"Under investigation" doesn't necessarily mean that the product is affected by this vulnerability. It only means that our Analysis Team is still working on determining whether the product is affected and how it is affected.
The term 'Affected' means that our Analysis team has determined that this product, such as Red Hat Enterprise Linux 8 or OpenShift Container Platform 4, is affected by this vulnerability and a fix may be released to address this issue in the near future. This includes all minor releases of this product unless noted otherwise in the Statement text.
Upgrade to a supported product version that includes a fix for this vulnerability (recommended).
Apply a mitigation (if one exists).
Customers with the Technical Account Manager (TAM) RHEL Security Select Add-on can review this CVE directly with their TAM.
Apply a mitigation (if one exists).
Red Hat Engineering focuses on addressing high-priority issues based on the impact and product lifecycle expectations. Therefore, lower-priority issues will not receive immediate fixes.
Customers with the technical account manager (TAM) RHEL Security Select Add-on can review this CVE directly with their TAM.
Not sure what something means? Check out our Security Glossary .
For clarification or corrections, please Red Hat Product Security .
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
