Description
An OS command injection flaw was found in the set_hostname_internal function of NooBaa's cluster_internal_api. This component is responsible for managing the Multi-Cloud Object Gateway in OpenShift Data Foundation. The vulnerability occurs because the hostname parameter is passed directly to a shell command without proper sanitization. An authenticated attacker with administrative privileges can provide a specially crafted hostname containing shell metacharacters to execute arbitrary commands on the host system with the privileges of the NooBaa process.
Published: 2026-09-28
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Assess Impact
AI Analysis

Impact

An operating‑system command injection flaw exists in NooBaa’s cluster_internal_api.set_hostname_internal function. The hostname value supplied by an attacker is passed directly to a shell command without sanitization, enabling an authenticated user with administrative privileges to inject shell metacharacters and execute arbitrary commands on the host system with the privileges of the NooBaa process.

Affected Systems

The vulnerability affects Red Hat Openshift Data Foundation 4, specifically the NooBaa core component that manages the Multi‑Cloud Object Gateway. No specific version numbers are listed in the CNA data, so all installed instances of the default 4.x release are considered potentially affected.

Risk and Exploitability

The CVSS score of 7.2 indicates a high‑severity flaw, but the EPSS score is not available and it is not listed in the CISA KEV catalog. The attack requires local administrative authentication, so the likelihood of exploitation depends on the exposure of privileged accounts. If exploited, the attacker can gain host‑level control, leading to full system compromise.

Generated by OpenCVE AI on September 28, 2026 at 13:50 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.


OpenCVE Recommended Actions

  • Update to a patched or newer version of Red Hat Openshift Data Foundation that removes the command‑execution path in set_hostname_internal
  • Restrict administrative access to the NooBaa process and enforce least‑privilege principles for users allowed to cause hostname changes
  • Disable or isolate the set_hostname_internal API by configuring network firewalls or service segmentation to block unauthenticated or non‑admin access
  • Implement monitoring of host processes for unexpected if modifying the source code is possible
  • No official workaround is available; rely on patching

Generated by OpenCVE AI on September 28, 2026 at 13:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Description An OS command injection flaw was found in the set_hostname_internal function of NooBaa's cluster_internal_api. This component is responsible for managing the Multi-Cloud Object Gateway in OpenShift Data Foundation. The vulnerability occurs because the hostname parameter is passed directly to a shell command without proper sanitization. An authenticated attacker with administrative privileges can provide a specially crafted hostname containing shell metacharacters to execute arbitrary commands on the host system with the privileges of the NooBaa process.
Title Noobaa-core: noobaa-core: os command injection in cluster_internal_api.set_hostname_internal
First Time appeared Redhat
Redhat openshift Data Foundation
Weaknesses CWE-78
CPEs cpe:/a:redhat:openshift_data_foundation:4
Vendors & Products Redhat
Redhat openshift Data Foundation
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Redhat Openshift Data Foundation
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-28T12:18:30.375Z

Reserved: 2026-09-07T07:04:20.475Z

Link: CVE-2026-86330

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-28T13:17:24.787

Modified: 2026-09-28T13:17:24.787

Link: CVE-2026-86330

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T14:00:17Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')