Skip to content
Critical OS Command Injection Flaw in Red Hat OpenShift Data Foundation

Critical OS Command Injection Flaw in Red Hat OpenShift Data Foundation

First seen 28 Sep 2026, 17:08 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 28, 2026 at 17:10 UTC
  • •CVE-2026-86330 allows command injection via unsanitized hostname input.
  • •Exploitation requires administrative privileges, posing risks to OpenShift environments.
  • •No effective mitigation or patch is currently available from Red Hat.

A significant OS command injection vulnerability, CVE-2026-86330, has been identified in the set_hostname_internal function of NooBaa's cluster_internal_api, part of Red Hat OpenShift Data Foundation. This flaw allows an authenticated attacker with administrative privileges to execute arbitrary commands on the host system by providing a specially crafted hostname. The vulnerability arises from the lack of proper sanitization of the hostname parameter before it is passed to a shell command. Red Hat has classified the severity of this vulnerability as Important, indicating that exploitation requires administrative access. Currently, no mitigation strategies are available that meet Red Hat's criteria for ease of use and stability. The vulnerability could lead to unauthorized code execution, data exposure, and service disruption. Administrators are advised to monitor for unusual activity and restrict access to the administrative API until a fix is available.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-09-28
CVE-2026-86330 published
Red Hat disclosed an OS command injection vulnerability affecting NooBaa's cluster_internal_api in OpenShift Data Foundation.
access.redhat.com
2026-09-28
CVE-2026-86330 reported by Red Packet Security
Red Packet Security issued an alert on the command injection flaw, highlighting the urgency for remediation.
Redpacketsecurity

More articles in this cluster (2)

Following this threat?

Track Red Hat and CVE-2026-86330 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed