Sceawere
Vulnerability Detail
CVE-2026-86330UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
NooBaa OS Command Injection
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.2
- Creation Date
- 3h ago
- Vendor
- Red Hat
- Product
- Red Hat Openshift Data Foundation 4
- Attack Type
- Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
An OS command injection flaw was found in the set_hostname_internal function of NooBaa's cluster_internal_api. This component is responsible for managing the Multi-Cloud Object Gateway in OpenShift Data Foundation. The vulnerability occurs because the hostname parameter is passed directly to a shell command without proper sanitization. An authenticated attacker with administrative privileges can provide a specially crafted hostname containing shell metacharacters to execute arbitrary commands on the host system with the privileges of the NooBaa process.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.2",
"pubDate": "2026-09-28T13:17:24.787Z",
"pubdate": "2026-09-28T13:17:24.787Z",
"executiveSummary": "An OS command injection vulnerability exists within the set_hostname_internal function of the NooBaa cluster_internal_api, a core component of the Multi-Cloud Object Gateway in OpenShift Data Foundation.\nThe vulnerability arises from the improper sanitization of the hostname parameter before it is passed to a system shell execution context. This flaw allows an authenticated user with administrative privileges to bypass input validation and execute arbitrary commands on the underlying host operating system.\nSuccessful exploitation results in full code execution with the permissions of the NooBaa process, potentially compromising the integrity, confidentiality, and availability of the Multi-Cloud Object Gateway.\nThis vulnerability is restricted to authenticated attackers who possess administrative access to the management interface, as they must be able to invoke the specific API function to provide a malicious hostname payload.",
"technicalDetails": "The root cause of the vulnerability is an unsafe interaction between the NooBaa application logic and the host system shell within the set_hostname_internal function. The application accepts a hostname parameter provided by the user and incorporates it directly into a command string intended for system-level execution without adequate character filtering, escaping, or parameterization.\nWhen the set_hostname_internal function is invoked, the application logic constructs a shell command designed to modify the cluster hostname. Because the input parameter is not treated as data, but rather interpreted as part of the command syntax, an attacker can supply shell metacharacters—such as semicolons (;), pipes (|), or backticks (`)—to terminate the intended command and append malicious shell instructions.\nThe attack flow proceeds as follows: First, an authenticated administrative user accesses the cluster_internal_api interface. Second, the user crafts an API request where the hostname parameter contains an injected payload (e.g., '; rm -rf /;'). Third, the set_hostname_internal function receives this input and executes the resulting malformed string via a call to a system or exec-family process wrapper. Finally, the shell interprets the injected commands, executing them with the UID/GID of the NooBaa service account.\nThe component responsible for this flaw is the cluster_internal_api, which acts as a bridge for administrative management tasks. Because the NooBaa process often runs with sufficient privileges to manage containerized infrastructure or underlying host settings, the successful injection allows for the execution of arbitrary commands, facilitating post-exploitation activities such as privilege escalation, lateral movement within the OpenShift environment, or persistent unauthorized access to the node.\nThis vulnerability requires authenticated access, specifically administrative rights, to reach the vulnerable API endpoint. There is no requirement for network-level access if the management interface is localized, but any exposure of the management API increases the attack surface. Payload execution is synchronous with the API call, and the resulting process behavior mirrors the standard operations of the shell environment, which may complicate detection via traditional signature-based security tools."
}