---
id: CVE-2026-54100
title: >-
  A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat
  OpenShift Container Platform
summary: >-
  A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat
  OpenShift Container Platform. WMCO establishes SSH connections to Windows
  worker nodes without verifying the remote server host key. An adjacent-network
  attacker …
severity: high
cvss: 8.3
cvssVector: 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-295
vendor: redhat
product: openshift_container_platform
affected:
  - 'openshift_container_platform >= 4.0, <= 4.22.1'
  - windows_machine_config_operator
patched:
  - openshift_for_windows_containers 10.21
  - openshift_for_windows_containers 10.22
published: '2026-06-22'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T13:20:30.487'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-54100'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:47173'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:61780'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2026-54100'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2487953'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:47173'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:61780'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/security/cve/CVE-2026-54100'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2487953'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54100.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-54100'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-54100'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-06-22T00:00:00+00:00'
epss: 0.00299
epssPercentile: 0.2009
ingestedAt: '2026-07-29T13:46:57.226Z'
---

## Overview

A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishes SSH connections to Windows worker nodes without verifying the remote server host key. An adjacent-network attacker who can intercept or redirect WMCO's SSH session can capture WICD and kubelet bootstrap credentials transferred during node configuration, enabling compromise of Windows node identities in the cluster.

## Affected

- `openshift_container_platform >= 4.0, <= 4.22.1`
- `windows_machine_config_operator`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2026:61780** · Red Hat · fixed in: Red Hat OpenShift for Windows Containers 10.21 · released 2026-08-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:61780)
- **RHSA-2026:47173** · Red Hat · fixed in: Red Hat OpenShift for Windows Containers 10.22 · released 2026-07-28 · [advisory](https://access.redhat.com/errata/RHSA-2026:47173)
- **Red Hat VEX** · Important · affected: Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat OpenShift Container Platform 4 · updated 2026-09-08 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54100.json)
