---
id: CVE-2026-54099
title: >-
  A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat
  OpenShift Container Platform
summary: >-
  A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat
  OpenShift Container Platform. The WICD CSR auto-approver validates that a
  Certificate Signing Request contains the organization system:wicd-nodes but
  does not rej…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-269
vendor: redhat
product: openshift_container_platform
affected:
  - 'openshift_container_platform >= 4.0, < 4.22.1'
  - windows_machine_config_operator
patched:
  - openshift_container_platform 4.22.1
published: '2026-06-22'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T13:20:30.257'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-54099'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:47173'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:61780'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2026-54099'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2487950'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:47173'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:61780'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/security/cve/CVE-2026-54099'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2487950'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54099.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-54099'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-54099'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-06-22T00:00:00+00:00'
epss: 0.0011
epssPercentile: 0.01419
ingestedAt: '2026-07-29T13:46:57.117Z'
---

## Overview

A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-approver validates that a Certificate Signing Request contains the organization system:wicd-nodes but does not reject additional organization values such as system:masters. A compromised Windows worker node that holds WICD credentials can submit a CSR that is auto-approved and signed by the cluster, yielding a client certificate that grants cluster-administrator privileges and enabling full cluster takeover.

## Affected

- `openshift_container_platform >= 4.0, < 4.22.1`
- `windows_machine_config_operator`

## Remediation

Upgrade past the affected range:

- `openshift_container_platform 4.22.1`

## Vendor advisories

- **RHSA-2026:61780** · Red Hat · fixed in: Red Hat OpenShift for Windows Containers 10.21 · released 2026-08-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:61780)
- **RHSA-2026:47173** · Red Hat · fixed in: Red Hat OpenShift for Windows Containers 10.22 · released 2026-07-28 · [advisory](https://access.redhat.com/errata/RHSA-2026:47173)
- **Red Hat VEX** · Important · affected: Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat OpenShift Container Platform 4 · updated 2026-09-08 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54099.json)
