PT-2026-76672 · Openshift Metal3 · Fakefish

CVE-2026-71567

·

Published

2026-08-17

·

Updated

2026-08-17

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions openshift-metal3/fakefish (affected versions not specified)
Description Certain scripts contain a repeated pattern where shell variables are injected into command lines or manifests without proper quoting. This issue primarily affects the Image URL and BMC credentials, which are not verified by the system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-71567

Affected Products

Fakefish