Path Traversal Vulnerability in Kubernetes kubectl Client for Windows
CVE-2026-19444

6.5MEDIUM

Key Information:

Vendor

Kubernetes

Vendor
CVE Published:
28 September 2026

What is CVE-2026-19444?

A path traversal vulnerability has been identified in the Kubernetes kubectl client's cp command on Windows systems. This vulnerability occurs when copying files from a container where the tar binary may be compromised. As a result, an attacker controlling the container contents can execute arbitrary code on the local machine of the user invoking the command. This ability to write files to arbitrary paths is hazardous, as it is limited only by the local user's system permissions, exposing systems to potential data breaches and unauthorized access.

Affected Version(s)

Kubernetes Windows v1.36.0

Kubernetes Windows v1.35.0

Kubernetes Windows v1.34.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Moriel Harush
Vyom Yadav
Maciej Szulik
Marly Salazar
.