{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-86330","assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","state":"PUBLISHED","assignerShortName":"redhat","dateReserved":"2026-09-07T07:04:20.475Z","datePublished":"2026-09-28T12:18:30.375Z","dateUpdated":"2026-09-30T20:11:12.424Z"},"containers":{"cna":{"title":"Noobaa-core: noobaa-core: os command injection in cluster_internal_api.set_hostname_internal","metrics":[{"other":{"content":{"value":"Important","namespace":"https://access.redhat.com/security/updates/classification/"},"type":"Red Hat severity rating"}},{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.2,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"HIGH","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"format":"CVSS"}],"descriptions":[{"lang":"en","value":"An OS command injection flaw was found in the set_hostname_internal function of NooBaa's cluster_internal_api. This component is responsible for managing the Multi-Cloud Object Gateway in OpenShift Data Foundation. The vulnerability occurs because the hostname parameter is passed directly to a shell command without proper sanitization. An authenticated attacker with administrative privileges can provide a specially crafted hostname containing shell metacharacters to execute arbitrary commands on the host system with the privileges of the NooBaa process."}],"affected":[{"vendor":"Red Hat","product":"Red Hat Openshift Data Foundation 4","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"odf4/mcg-core-rhel9","defaultStatus":"affected","cpes":["cpe:/a:redhat:openshift_data_foundation:4"]},{"vendor":"Red Hat","product":"Red Hat Openshift Data Foundation 4","collectionURL":"https://access.redhat.com/downloads/content/package-browser/","packageName":"rhceph-dev/odf4-mcg-core-rhel9","defaultStatus":"affected","cpes":["cpe:/a:redhat:openshift_data_foundation:4"]}],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-86330","tags":["vdb-entry","x_refsource_REDHAT"]},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2529295","name":"RHBZ#2529295","tags":["issue-tracking","x_refsource_REDHAT"]}],"datePublic":"2026-09-28T11:55:43.935Z","problemTypes":[{"descriptions":[{"cweId":"CWE-78","description":"Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')","lang":"en","type":"CWE"}]}],"x_redhatCweChain":"CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')","workarounds":[{"lang":"en","value":"Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability."}],"timeline":[{"lang":"en","time":"2026-09-07T07:03:36.704Z","value":"Reported to Red Hat."},{"lang":"en","time":"2026-09-28T11:55:43.935Z","value":"Made public."}],"credits":[{"lang":"en","value":"Red Hat would like to thank Antoine ARDINO (Elweth) for reporting this issue."}],"providerMetadata":{"orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat","dateUpdated":"2026-09-28T12:18:30.375Z"},"x_generator":{"engine":"cvelib 1.8.0"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"id":"CVE-2026-86330","role":"CISA Coordinator","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"version":"2.0.3","timestamp":"2026-09-30T19:41:30.611110Z"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-09-30T20:11:12.424Z"}}]}}