Path Traversal Vulnerability in Kubernetes kubectl Client for Windows
CVE-2026-19444
6.5MEDIUM
What is CVE-2026-19444?
A path traversal vulnerability has been identified in the Kubernetes kubectl client's cp command on Windows systems. This vulnerability occurs when copying files from a container where the tar binary may be compromised. As a result, an attacker controlling the container contents can execute arbitrary code on the local machine of the user invoking the command. This ability to write files to arbitrary paths is hazardous, as it is limited only by the local user's system permissions, exposing systems to potential data breaches and unauthorized access.
Affected Version(s)
Kubernetes Windows v1.36.0
Kubernetes Windows v1.35.0
Kubernetes Windows v1.34.0
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Moriel Harush
Vyom Yadav
Maciej Szulik
Marly Salazar