What is CVE-2026-71567?
CVE-2026-71567 is a vulnerability in OpenShift-metal3/fakefish where shell variables, primarily Image URL and BMC credentials, are injected without quoting into commands or manifests. This insecure pattern could lead to command injection risks. Users should ensure proper quoting of variables in affected scripts.
Azərbaycanca: CVE-2026-71567, OpenShift-metal3/fakefish skriptlərində shell dəyişənlərinin düzgün quotinq edilməməsi ilə bağlı zəiflikdir. Bu, Image URL və BMC kredensiallarının təhlükəsiz olmayan şəkildə istifadəsinə səbəb olur ki, bu da potensial olaraq əmr inyeksiyası riskləri yarada bilər. Bu konfiqurasiyaları istifadə edən istifadəçilər skriptlərdə dəyişənlərin düzgün quotinq edildiyindən əmin olmalıdırlar.
Related CVEs
link basis: same weakness class CWE-77
FAQ2
Which data is used insecurely in OpenShift-metal3/fakefish due to CVE-2026-71567?
CVE-2026-71567 leads to insecure usage of Image URL and BMC credentials due to improper quoting in scripts.
What is the potential risk of CVE-2026-71567?
This vulnerability could lead to command injection risks due to shell variables being injected without quoting.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.