PT-2026-76666 · Fakefish+1 · Fakefish+1

CVE-2026-71566

·

Published

2026-08-17

·

Updated

2026-08-17

CVSS v3.1

9.3

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions FakeFish (affected versions not specified)
Description FakeFish processes incoming credentials by passing them to scripts. While this is effective for physical hardware where the Baseboard Management Controller (BMC) validates the credentials, KubeVirt relies on a mounted KUBECONFIG file and ignores the provided credentials. This flaw allows any cluster user to control virtual machines created by the FakeFish user, including powering them on or off and mounting arbitrary CD images.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-71566

Affected Products

Fakefish
Kubevirt