PT-2026-96189 · Kubeedge · Kubeedge

CVE-2026-62182

·

Published

2026-09-21

·

Updated

2026-10-01

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions KubeEdge versions 1.21.0 through 1.21.1 KubeEdge versions 1.22.0 through 1.22.1 KubeEdge versions 1.23.0 through 1.23.0
Description ConfigUpdateJob processing in edge/pkg/taskmanager/actions/configupdatejob.go concatenates authenticated user-controlled updateFields values into the keadm config-update command and executes it through a system shell. An authenticated user with permissions to create or modify ConfigUpdateJob resources can inject shell metacharacters into the --set value, leading to arbitrary command execution on an enrolled target edge node with the privileges of the KubeEdge process handling the job.
Recommendations Update to version 1.21.2. Update to version 1.22.2. Update to version 1.23.1.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-62182
GHSA-M3C6-2P7H-CFR3
GO-2026-6573

Affected Products

Kubeedge