Arbitrary Command Execution Vulnerability in KubeEdge by KubeEdge
CVE-2026-62371

8.8HIGH

Key Information:

Vendor

Kubeedge

Status
Vendor
CVE Published:
21 September 2026

What is CVE-2026-62371?

KubeEdge, an open-source system for extending containerized application orchestration to edge hosts, has a significant vulnerability that allows attackers to exploit the v1alpha2 NodeUpgradeJob handler. This issue arises when a user with permissions to create or update NodeUpgradeJob resources can inject shell metacharacters through user-controlled parameters. When version and image values are concatenated into the upgrade command, this can lead to arbitrary commands being executed with the privileges of the upgrade process on targeted edge nodes, impairing node confidentiality, integrity, and availability. The vulnerability has been addressed in versions 1.21.2, 1.22.2, and 1.23.1.

Affected Version(s)

kubeedge >= 1.12.0, < 1.21.2 < 1.12.0, 1.21.2

kubeedge >= 1.22.0, < 1.22.2 < 1.22.0, 1.22.2

kubeedge >= 1.23.0, < 1.23.1 < 1.23.0, 1.23.1

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.