An authenticated tenant with basic namespace permissions can break out to the host control plane in OpenShift clusters running Multicluster Engine with HyperShift.
CVE-2026-101919 (CVSS 3.1 8.8, Red Hat: Important) is an improper input validation flaw in the hypershift-rhel9-operator. The ReconcileCredentials function copies a user-provided kubeconfig Secret verbatim into the privileged control plane namespace:
// illustrative — simplified from source
for k, v := range sourceSecret.Data {
targetSecret.Data[k] = v
}
No exec-provider stripping, no AuthProvider validation, no InsecureSkipTLSVerify guard. A tenant embeds a malicious exec plugin in their kubeconfig → operator copies it to the control plane namespace → downstream controller (CAPK) consumes it → plugin executes with control plane privileges.
Impact:
Arbitrary code execution in the control plane namespace
Access to all control plane secrets
Lateral movement across tenant boundaries
Tenant isolation guarantee defeated
No public PoC. Patch is available.
Immediate mitigations:
Patch the HyperShift operator via your cluster update mechanism
Restrict Secret creation to trusted accounts in HyperShift-watched namespaces
Deploy admission webhook to reject kubeconfig Secrets containing exec plugins
Audit existing kubeconfig Secrets for embedded plugins
Full analysis: https://threataft.com/articles/hypershift-tenant-isolation-bypass-cve-2026-101919
Top comments (0)