Arbitrary Command Execution Vulnerability in KubeEdge by KubeEdge
CVE-2026-62371
What is CVE-2026-62371?
KubeEdge, an open-source system for extending containerized application orchestration to edge hosts, has a significant vulnerability that allows attackers to exploit the v1alpha2 NodeUpgradeJob handler. This issue arises when a user with permissions to create or update NodeUpgradeJob resources can inject shell metacharacters through user-controlled parameters. When version and image values are concatenated into the upgrade command, this can lead to arbitrary commands being executed with the privileges of the upgrade process on targeted edge nodes, impairing node confidentiality, integrity, and availability. The vulnerability has been addressed in versions 1.21.2, 1.22.2, and 1.23.1.
Affected Version(s)
kubeedge >= 1.12.0, < 1.21.2 < 1.12.0, 1.21.2
kubeedge >= 1.22.0, < 1.22.2 < 1.22.0, 1.22.2
kubeedge >= 1.23.0, < 1.23.1 < 1.23.0, 1.23.1
