CVE-2026-62369
Last modified
CVE-2026-62369 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.16.0 until 1.21.2, 1.22.2, and 1.23.1, the DecompressTarGz function in keadm/cmd/keadm/app/cmd/util/common.go joins archive entry names to the extraction destination without sufficient validation. EPSS estimates a 0.86% chance of exploitation in the next 30 days.
Description
KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.16.0 until 1.21.2, 1.22.2, and 1.23.1, the DecompressTarGz function in keadm/cmd/keadm/app/cmd/util/common.go joins archive entry names to the extraction destination without sufficient validation. During keadm join or installation on Windows edge nodes, an archive influenced through a compromised, replaced, or untrusted download source can contain parent-directory components, Windows-style backslashes, absolute paths, or drive-prefixed paths that escape the intended directory. The affected keadm process can consequently write or overwrite files with its own privileges, potentially modifying configuration, executable, or service files and enabling persistent system modification or code execution. This issue is fixed in versions 1.21.2, 1.22.2, and 1.23.1.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| kubeedge | kubeedge | >= 1.16.0, < 1.21.2; >= 1.22.0, < 1.22.2; >= 1.23.0, < 1.23.1 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-62369?
How severe is CVE-2026-62369?
How do I fix CVE-2026-62369?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-62357Dragonfly is an in-memory data store built for modern applic…8.8
- CVE-2026-6236The Posts map plugin for WordPress is vulnerable to Stored C…6.4
- CVE-2026-62361listmonk is a standalone, self-hosted, newsletter and mailin…5.5
- CVE-2026-62363ImageMagick is free and open-source software used for editin…5
- CVE-2026-62364wlc is a Weblate command-line client using Weblate's REST AP…2.3
- CVE-2026-62368Snipe-IT is an IT asset/license management system. Prior to …8.1
- CVE-2026-6237The Quick Table plugin for WordPress is vulnerable to Stored…6.4
- CVE-2026-62370KubeEdge is an open source system for extending native conta…6.5
- CVE-2026-62371KubeEdge is an open source system for extending native conta…8.8
- CVE-2026-62377libheif is a HEIF and AVIF file format decoder and encoder. …4.3
- CVE-2026-62378RustFS Console is a web management console for the RustFS di…9
- CVE-2026-62379Open Access Management (OpenAM) is an access management solu…9.8
Are you affected by CVE-2026-62369?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
