rootpwn

high · CVSS v3 7.2

CVE-2026-86330

An OS command injection flaw was found in the set_hostname_internal function of NooBaa's cluster_internal_api. This comp…

Description

An OS command injection flaw was found in the set_hostname_internal function of NooBaa's cluster_internal_api. This component is responsible for managing the Multi-Cloud Object Gateway in OpenShift Data Foundation. The vulnerability occurs because the hostname parameter is passed directly to a shell command without proper sanitization. An authenticated attacker with administrative privileges can provide a specially crafted hostname containing shell metacharacters to execute arbitrary commands on the host system with the privileges of the NooBaa process.

Scores

Severity
high
CVSS v2
8.3
CVSS v3
7.2
CVSS v4
—
EPSS
—

← All CVEs