Database/Control plane, storage & DevOps
Red Hat OpenShift Windows Machine Config Operator (unverified SSH host key): WMCO opens SSH to Windows worker nodes
CVE-2026-54100Control plane, storage & DevOpscurated
Impact
WMCO opens SSH to Windows worker nodes without verifying the host key, so an adjacent-network attacker intercepting the session captures WICD and kubelet bootstrap credentials - which is cluster-node identity, with scope change.
Who can reach it
Adjacent network position able to intercept or redirect WMCO's SSH session to a Windows node.
What to do
Apply RHSA-2026:47173. Operator update; afterwards rotate kubelet bootstrap credentials for Windows nodes, because captured bootstrap tokens remain valid until rotated.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.