CVE-2026-86330
Last modified
CVE-2026-86330 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. An OS command injection flaw was found in the set_hostname_internal function of NooBaa's cluster_internal_api. This component is responsible for managing the Multi-Cloud Object Gateway in OpenShift Data Foundation.
Description
An OS command injection flaw was found in the set_hostname_internal function of NooBaa's cluster_internal_api. This component is responsible for managing the Multi-Cloud Object Gateway in OpenShift Data Foundation. The vulnerability occurs because the hostname parameter is passed directly to a shell command without proper sanitization. An authenticated attacker with administrative privileges can provide a specially crafted hostname containing shell metacharacters to execute arbitrary commands on the host system with the privileges of the NooBaa process.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat Openshift Data Foundation 4 | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-86330?
How severe is CVE-2026-86330?
How do I fix CVE-2026-86330?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-86318A flaw has been found in java-json-tools json-patch up to 1.…5.3
- CVE-2026-86319A vulnerability has been found in java-json-tools json-patch…5.3
- CVE-2026-8632A potential security vulnerability has been identified in th…7.8
- CVE-2026-86320A flaw was found in flatpak-builder where Git hooks are not …7.8
- CVE-2026-86321A vulnerability was found in java-json-tools jackson-coreuti…5.3
- CVE-2026-8633IBM Web Server Plug-ins for WebSphere Application Server and…9.8
- CVE-2026-86332A flaw was found in odh-dashboard in Red Hat OpenShift AI. T…6.5
- CVE-2026-86334Path traversal in the CLI client image export and copy funct…4.2
- CVE-2026-86335Missing Authorization in imageDownload in Canonical LXD befo…6.3
- CVE-2026-86338Ash field_policies are documented to protect against filter-…6
- CVE-2026-8634Crabbox prior to v0.12.0 contains an environment variable ex…9.3
- CVE-2026-86341GitLab has remediated an issue in GitLab EE affecting all ve…4.4
Are you affected by CVE-2026-86330?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
