Red Hat · Noobaa · CVE-2026-86330
**Name of the Vulnerable Software and Affected Versions**
NooBaa (affected versions not specified)
**Description**
An OS command injection flaw exists in the `set hostname internal()` function of the 'cluster internal api' component, which manages the Multi-Cloud Object Gateway in OpenShift Data Foundation. The issue arises because the `hostname` parameter is passed to a shell command without proper sanitization. An authenticated attacker with administrative privileges can use a specially crafted `hostname` containing shell metacharacters to execute arbitrary commands on the host system with the privileges of the NooBaa process.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.