HyperShift CVE-2026-101919: CVSS 8.8 tenant isolation bypass
OpenShift clusters running Multicluster Engine with HyperShift are affected by CVE-2026-101919 (CVSS 8.8, Red Hat Important). The ReconcileCredentials function copies a user-supplied kubeconfig Secret verbatim into the privileged control plane namespace, letting a tenant with basic namespace permissions execute code there.
- CVSS 3.1 score of 8.8, rated Important by Red Hat
- Tenant with basic namespace rights breaks out to control plane
- ReconcileCredentials copies kubeconfig without exec-plugin checks
- Fix: update the hypershift-rhel9-operator via cluster update
Read next
Security