{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Important"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Copyright © Red Hat, Inc. All rights reserved.",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54099.json"
      }
    ],
    "title": "windows-machine-config-operator: windows-machine-config-operator: WICD CSR extra-Organization allows privilege escalation to system:masters",
    "tracking": {
      "current_release_date": "2026-07-28T16:03:22+00:00",
      "generator": {
        "date": "2026-07-28T16:03:22+00:00",
        "engine": {
          "name": "Red Hat SDEngine",
          "version": "5.3.7"
        }
      },
      "id": "CVE-2026-54099",
      "initial_release_date": "2026-06-10T00:00:00+00:00",
      "revision_history": [
        {
          "date": "2026-06-10T00:00:00+00:00",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-06-22T14:01:44+00:00",
          "number": "2",
          "summary": "Current version"
        },
        {
          "date": "2026-07-28T16:03:22+00:00",
          "number": "3",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "3"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat OpenShift Container Platform 4",
                "product": {
                  "name": "Red Hat OpenShift Container Platform 4",
                  "product_id": "red_hat_openshift_container_platform_4",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:openshift:4"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat OpenShift Container Platform 4"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat OpenShift for Windows Containers 10.22",
                "product": {
                  "name": "Red Hat OpenShift for Windows Containers 10.22",
                  "product_id": "Red Hat OpenShift for Windows Containers 10.22",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:windows_machine_config:10.22::el9"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat OpenShift for Windows Containers"
          },
          {
            "category": "product_version",
            "name": "openshift4-wincw/windows-machine-config-rhel8-operator",
            "product": {
              "name": "openshift4-wincw/windows-machine-config-rhel8-operator",
              "product_id": "openshift4-wincw/windows-machine-config-rhel8-operator",
              "product_identification_helper": {
                "purl": "pkg:oci/windows-machine-config-rhel8-operator@10.16.1-2.1745841799?repository_url=registry.redhat.io/openshift4-wincw/windows-machine-config-rhel8-operator"
              }
            }
          },
          {
            "category": "product_version",
            "name": "openshift4-wincw/windows-machine-config-rhel9-operator",
            "product": {
              "name": "openshift4-wincw/windows-machine-config-rhel9-operator",
              "product_id": "openshift4-wincw/windows-machine-config-rhel9-operator",
              "product_identification_helper": {
                "purl": "pkg:oci/windows-machine-config-rhel9-operator@10.16.1-2.1745841799?repository_url=registry.redhat.io/openshift4-wincw/windows-machine-config-rhel9-operator"
              }
            }
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "registry.redhat.io/openshift4-wincw/windows-machine-config-operator-bundle@sha256:6c20b766b0c63111d59d3c0b46b248e03f41a8fe2559f5c7a108cb1738f22b71_amd64",
                "product": {
                  "name": "registry.redhat.io/openshift4-wincw/windows-machine-config-operator-bundle@sha256:6c20b766b0c63111d59d3c0b46b248e03f41a8fe2559f5c7a108cb1738f22b71_amd64",
                  "product_id": "registry.redhat.io/openshift4-wincw/windows-machine-config-operator-bundle@sha256:6c20b766b0c63111d59d3c0b46b248e03f41a8fe2559f5c7a108cb1738f22b71_amd64",
                  "product_identification_helper": {
                    "purl": "pkg:oci/windows-machine-config-operator-bundle@sha256%3A6c20b766b0c63111d59d3c0b46b248e03f41a8fe2559f5c7a108cb1738f22b71?arch=amd64&repository_url=registry.redhat.io/openshift4-wincw/windows-machine-config-operator-bundle&tag=1783955949"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "registry.redhat.io/openshift4-wincw/windows-machine-config-rhel9-operator@sha256:3aacd9560f3408becf4b3618590a620d72aff0313a5efb23542552a6fd59500f_amd64",
                "product": {
                  "name": "registry.redhat.io/openshift4-wincw/windows-machine-config-rhel9-operator@sha256:3aacd9560f3408becf4b3618590a620d72aff0313a5efb23542552a6fd59500f_amd64",
                  "product_id": "registry.redhat.io/openshift4-wincw/windows-machine-config-rhel9-operator@sha256:3aacd9560f3408becf4b3618590a620d72aff0313a5efb23542552a6fd59500f_amd64",
                  "product_identification_helper": {
                    "purl": "pkg:oci/windows-machine-config-rhel9-operator@sha256%3A3aacd9560f3408becf4b3618590a620d72aff0313a5efb23542552a6fd59500f?arch=amd64&repository_url=registry.redhat.io/openshift4-wincw/windows-machine-config-rhel9-operator&tag=1783692800"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          }
        ],
        "category": "vendor",
        "name": "Red Hat"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "registry.redhat.io/openshift4-wincw/windows-machine-config-operator-bundle@sha256:6c20b766b0c63111d59d3c0b46b248e03f41a8fe2559f5c7a108cb1738f22b71_amd64 as a component of Red Hat OpenShift for Windows Containers 10.22",
          "product_id": "Red Hat OpenShift for Windows Containers 10.22:registry.redhat.io/openshift4-wincw/windows-machine-config-operator-bundle@sha256:6c20b766b0c63111d59d3c0b46b248e03f41a8fe2559f5c7a108cb1738f22b71_amd64"
        },
        "product_reference": "registry.redhat.io/openshift4-wincw/windows-machine-config-operator-bundle@sha256:6c20b766b0c63111d59d3c0b46b248e03f41a8fe2559f5c7a108cb1738f22b71_amd64",
        "relates_to_product_reference": "Red Hat OpenShift for Windows Containers 10.22"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "registry.redhat.io/openshift4-wincw/windows-machine-config-rhel9-operator@sha256:3aacd9560f3408becf4b3618590a620d72aff0313a5efb23542552a6fd59500f_amd64 as a component of Red Hat OpenShift for Windows Containers 10.22",
          "product_id": "Red Hat OpenShift for Windows Containers 10.22:registry.redhat.io/openshift4-wincw/windows-machine-config-rhel9-operator@sha256:3aacd9560f3408becf4b3618590a620d72aff0313a5efb23542552a6fd59500f_amd64"
        },
        "product_reference": "registry.redhat.io/openshift4-wincw/windows-machine-config-rhel9-operator@sha256:3aacd9560f3408becf4b3618590a620d72aff0313a5efb23542552a6fd59500f_amd64",
        "relates_to_product_reference": "Red Hat OpenShift for Windows Containers 10.22"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openshift4-wincw/windows-machine-config-rhel8-operator as a component of Red Hat OpenShift Container Platform 4",
          "product_id": "red_hat_openshift_container_platform_4:openshift4-wincw/windows-machine-config-rhel8-operator"
        },
        "product_reference": "openshift4-wincw/windows-machine-config-rhel8-operator",
        "relates_to_product_reference": "red_hat_openshift_container_platform_4"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openshift4-wincw/windows-machine-config-rhel9-operator as a component of Red Hat OpenShift Container Platform 4",
          "product_id": "red_hat_openshift_container_platform_4:openshift4-wincw/windows-machine-config-rhel9-operator"
        },
        "product_reference": "openshift4-wincw/windows-machine-config-rhel9-operator",
        "relates_to_product_reference": "red_hat_openshift_container_platform_4"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-54099",
      "cwe": {
        "id": "CWE-269",
        "name": "Improper Privilege Management"
      },
      "discovery_date": "2026-06-11T00:00:00+00:00",
      "flags": [
        {
          "label": "vulnerable_code_not_present",
          "product_ids": [
            "Red Hat OpenShift for Windows Containers 10.22:registry.redhat.io/openshift4-wincw/windows-machine-config-operator-bundle@sha256:6c20b766b0c63111d59d3c0b46b248e03f41a8fe2559f5c7a108cb1738f22b71_amd64"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2487950"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-approver validates that a Certificate Signing Request contains the organization system:wicd-nodes but does not reject additional organization values such as system:masters. A compromised Windows worker node that holds WICD credentials can submit a CSR that is auto-approved and signed by the cluster, yielding a client certificate that grants cluster-administrator privileges and enabling full cluster takeover.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "windows-machine-config-operator: windows-machine-config-operator: WICD CSR extra-Organization allows privilege escalation to system:masters",
          "title": "Vulnerability summary"
        },
        {
          "category": "other",
          "text": "This flaw affects OpenShift clusters running the Windows Machine Config Operator (WMCO) with one or more Windows worker nodes. Clusters without Windows nodes or without WMCO are not affected. Exploitation requires compromising a Windows worker node and obtaining WICD credentials from that node. Red Hat Security Ratings classify this as Important because a successful attack grants cluster-administrator access from a compromised Windows node.",
          "title": "Statement"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Red Hat OpenShift for Windows Containers 10.22:registry.redhat.io/openshift4-wincw/windows-machine-config-rhel9-operator@sha256:3aacd9560f3408becf4b3618590a620d72aff0313a5efb23542552a6fd59500f_amd64"
        ],
        "known_affected": [
          "red_hat_openshift_container_platform_4:openshift4-wincw/windows-machine-config-rhel8-operator",
          "red_hat_openshift_container_platform_4:openshift4-wincw/windows-machine-config-rhel9-operator"
        ],
        "known_not_affected": [
          "Red Hat OpenShift for Windows Containers 10.22:registry.redhat.io/openshift4-wincw/windows-machine-config-operator-bundle@sha256:6c20b766b0c63111d59d3c0b46b248e03f41a8fe2559f5c7a108cb1738f22b71_amd64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-54099"
        },
        {
          "category": "external",
          "summary": "RHBZ#2487950",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487950"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-54099",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54099"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-54099",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54099"
        }
      ],
      "release_date": "2026-06-10T00:00:00+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-07-28T16:01:42+00:00",
          "details": "For Windows Machine Config Operator upgrades, see the following documentation: https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html/windows_container_support_for_openshift/windows-node-upgrades",
          "product_ids": [
            "Red Hat OpenShift for Windows Containers 10.22:registry.redhat.io/openshift4-wincw/windows-machine-config-rhel9-operator@sha256:3aacd9560f3408becf4b3618590a620d72aff0313a5efb23542552a6fd59500f_amd64"
          ],
          "url": "https://access.redhat.com/errata/RHSA-2026:47173"
        },
        {
          "category": "workaround",
          "details": "At this time, no mitigation or workaround is available for this vulnerability. Customers are advised to apply the appropriate updates as they become available.",
          "product_ids": [
            "Red Hat OpenShift for Windows Containers 10.22:registry.redhat.io/openshift4-wincw/windows-machine-config-rhel9-operator@sha256:3aacd9560f3408becf4b3618590a620d72aff0313a5efb23542552a6fd59500f_amd64",
            "red_hat_openshift_container_platform_4:openshift4-wincw/windows-machine-config-rhel8-operator",
            "red_hat_openshift_container_platform_4:openshift4-wincw/windows-machine-config-rhel9-operator"
          ]
        },
        {
          "category": "none_available",
          "details": "Affected",
          "product_ids": [
            "red_hat_openshift_container_platform_4:openshift4-wincw/windows-machine-config-rhel8-operator",
            "red_hat_openshift_container_platform_4:openshift4-wincw/windows-machine-config-rhel9-operator"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "Red Hat OpenShift for Windows Containers 10.22:registry.redhat.io/openshift4-wincw/windows-machine-config-operator-bundle@sha256:6c20b766b0c63111d59d3c0b46b248e03f41a8fe2559f5c7a108cb1738f22b71_amd64",
            "Red Hat OpenShift for Windows Containers 10.22:registry.redhat.io/openshift4-wincw/windows-machine-config-rhel9-operator@sha256:3aacd9560f3408becf4b3618590a620d72aff0313a5efb23542552a6fd59500f_amd64",
            "red_hat_openshift_container_platform_4:openshift4-wincw/windows-machine-config-rhel8-operator",
            "red_hat_openshift_container_platform_4:openshift4-wincw/windows-machine-config-rhel9-operator"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important",
          "product_ids": [
            "Red Hat OpenShift for Windows Containers 10.22:registry.redhat.io/openshift4-wincw/windows-machine-config-operator-bundle@sha256:6c20b766b0c63111d59d3c0b46b248e03f41a8fe2559f5c7a108cb1738f22b71_amd64",
            "Red Hat OpenShift for Windows Containers 10.22:registry.redhat.io/openshift4-wincw/windows-machine-config-rhel9-operator@sha256:3aacd9560f3408becf4b3618590a620d72aff0313a5efb23542552a6fd59500f_amd64",
            "red_hat_openshift_container_platform_4:openshift4-wincw/windows-machine-config-rhel8-operator",
            "red_hat_openshift_container_platform_4:openshift4-wincw/windows-machine-config-rhel9-operator"
          ]
        }
      ],
      "title": "windows-machine-config-operator: windows-machine-config-operator: WICD CSR extra-Organization allows privilege escalation to system:masters"
    }
  ]
}