Skip to content
CVE Alert: CVE-2026-86330 – Red Hat

CVE Alert: CVE-2026-86330 – Red Hat

Redpacketsecurity •admin • September 28, 2026

An OS command injection flaw was found in the set_hostname_internal function of NooBaa’s cluster_internal_api. This component is responsible for managing the Multi-Cloud Object Gateway in OpenShift Data Foundation. The vulnerability occurs because the hostname parameter is passed directly to a shell command without proper sanitization. An authenticated attacker with administrative privileges can provide a specially crafted hostname containing shell metacharacters to execute arbitrary commands on the host system with the privileges of the NooBaa process.

**Risk verdict:** Treat as a high-impact issue and plan rapid remediation; urgency cannot be fully assessed because KEV, SSVC, PoC and EPSS indicators were not provided.

**Why this matters:** Successful exploitation could let an authorised attacker run commands as the gateway process, risking data exposure, tampering or service disruption. Access to credentials or storage data depends on the process permissions and environment, so cluster-wide compromise should not be assumed.

**Most likely attack path:** An attacker needs network access and high privileges to invoke the administrative hostname-change operation; no user action is required, and exploitation is not complex once those conditions are met. The stated unchanged scope limits the direct security-authority impact, but stolen credentials or excessive service permissions could enable further movement.

**Who is most exposed:** Prioritise OpenShift environments running the affected object-storage gateway component, especially where many administrators or automation identities can invoke its internal API.

Review audit records for unexpected hostname-change requests or unfamiliar administrator identities.

Alert on gateway processes spawning shells or unexpected child processes.

Inspect process, container and node logs for shell metacharacters in hostname-related input.

Check for unusual outbound connections or access to secrets after suspicious activity.

Mitigation and prioritisation:

Apply the vendor’s fixed update as soon as available; confirm the installed component is covered.

No vendor-endorsed workaround is available; restrict administrative API access and reduce privileged accounts meanwhile.

Review gateway service permissions and rotate potentially exposed credentials if exploitation is suspected.

Test the update in a representative environment and schedule deployment to minimise storage-service disruption.

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.

Extracted Entities