Sceawere

Vulnerability Detail

CVE-2026-19444UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Kubectl Windows Path Traversal

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
4h ago
Vendor
Kubernetes
Product
Kubernetes
Attack Type
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Vector String
CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:C/C:L/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

A path traversal vulnerability was discovered in the Kubernetes kubectl client's kubectl cp command on Windows. When copying files from a container, kubectl runs tar inside the container to build a tar archive, transfers it over the network, and unpacks it on the local machine. If the tar binary in the container is malicious, it can execute arbitrary code and emit unexpected output, allowing an attacker who controls container contents to write files to arbitrary paths on the user's local machine when kubectl cp is invoked, limited only by the system permissions of the local user. This issue only affects kubectl clients running on Windows.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-09-28T12:17:36.723Z",
  "pubdate": "2026-09-28T12:17:36.723Z",
  "executiveSummary": "A path traversal vulnerability exists in the kubectl cp command for Windows, stemming from insecure handling of tar archives during container-to-host file transfers.\nThe vulnerability allows a malicious container to execute arbitrary code and overwrite files on the host machine by manipulating the tar stream processed by the kubectl client.\nThe scope is limited to kubectl clients operating on Windows environments where the user invokes kubectl cp to retrieve files from a compromised or malicious container.\nThe impact is significant, as an attacker with control over the container's tar utility can write files to any location accessible by the local user running the kubectl command, potentially leading to full system compromise or persistence.\nExploitation requires the victim to perform a kubectl cp operation against a malicious container, which then provides a crafted tar archive to the client.",
  "technicalDetails": "The root cause of this vulnerability is the trust-based assumption that the tar output emitted by a container is benign. When a user executes kubectl cp, the client interacts with the container's local tar binary to package the requested files into a tar archive. This archive is subsequently transmitted over the network and unpacked by the kubectl client on the local Windows machine.\nBecause the local kubectl process performs the extraction of the incoming tar stream without sufficient validation or sanitization of file paths contained within the archive headers, a malicious container can bypass directory restrictions.\nThe attack flow begins when an attacker controls the container environment. The attacker replaces or modifies the container's internal tar utility to generate headers containing path traversal sequences, such as '../' or absolute file paths. When kubectl cp is invoked to copy files from this container, the modified tar binary includes these malicious headers in the stream.\nUpon receiving this stream, the kubectl client on Windows attempts to unpack the files. Due to the lack of path normalization and validation logic in the Windows-specific implementation of the extraction routine, the client writes files outside the intended destination directory. Since Windows handles specific character sequences and path formats differently than POSIX systems, these traversal sequences effectively target arbitrary locations on the host filesystem.\nThe attack is limited by the permissions of the local user running the kubectl process. If the user possesses administrative privileges, the malicious payload can overwrite system files, place files in startup directories for persistence, or inject malicious libraries. Even with standard user privileges, an attacker can modify local configuration files, sensitive data, or user-specific startup items to achieve lateral movement or further exploitation.\nThis vulnerability highlights a critical failure in validating inputs derived from untrusted remote execution environments. By weaponizing the archive format, the attacker transitions from a restricted containerized environment to the host operating system, effectively breaking the container sandbox boundary through the administrative tool intended to facilitate data movement."
}
CVE-2026-19444: Kubectl Windows Path Traversal (MEDIUM Severity, CVSS: 6.5) | Sceawere