Skip to content
archivevulnerability · 22 Sep 2026 · 20:36 UTC

GHSA-m3c6-2p7h-cfr3: KubeEdge: ConfigUpdateJob updateFields enables remote shell injection and code execution on edge nodes

VULNCVE-2026-62182source · GTH
HIGHHigh-risk vulnerability — CVSS 8.8

last 60 dispatches · spectrum

## Description KubeEdge ConfigUpdateJob processing was vulnerable to command injection on edge nodes. The `updateFields` values from a ConfigUpdateJob were concatenated into a command string and executed through a system shell. An authenticated user with sufficient permissions to create or update ConfigUpdateJob resources could include shell metacharacters in the supplied configuration fields and cause unintended commands to be executed on targeted edge nodes. …

CVE · detail
grounded ✓primary source ↗
Early access

Get the next one first.

Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.

bot-protected