CVE-2026-19444
A path traversal vulnerability was discovered in the Kubernetes kubectl client's kubectl cp command on Windows. When copying files from a container, kubectl runs tar inside the container to build a tar archive, transfers it over the network, and unpacks it on the local machine. If the tar binary in the container is malicious, it can execute arbitrary code and emit unexpected output, allowing an attacker who controls container contents to write files to arbitrary paths on the user's local machine when kubectl cp is invoked, limited only by the system permissions of the local user. This issue only affects kubectl clients running on Windows.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:C/C:L/I:H/A:N
- Base score: 6.5
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.20%
- Percentile among all scored CVEs: 9
- Score date: 10/6/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
🎯 ATT&CK techniques
How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.
- Exploitation
T1203Exploitation for Client Executionexecution85 % - Primary impact
T1565.001Stored Data Manipulationimpact80 % - Secondary impact
T1059.003Windows Command Shellexecution75 %
Requiere interacción del usuario (kubectl cp) y control del contenedor. Impacto principal: escritura arbitraria de archivos (T1565.001); secundario: ejecución de código mediante tar malicioso (T1059.003).
Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.
🛡️ ATT&CK mitigations that cover these techniques
Affected technologies (1)
⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.
CWEs
- CWE-22
References
Raw JSON (NVD)
Show
{
"id": "CVE-2026-19444",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-19444",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-09-28T18:08:52.660901Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "jordan@liggitt.net",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "ADJACENT_NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:C/C:L/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "HIGH",
"confidentialityImpact": "LOW"
},
"impactScore": 4.7,
"exploitabilityScore": 1.2
}
]
},
"affected": [
{
"source": "jordan@liggitt.net",
"affectedData": [
{
"repo": "https://github.com/kubernetes/kubernetes",
"vendor": "Kubernetes",
"product": "Kubernetes",
"versions": [
{
"status": "affected",
"version": "v1.36.0",
"versionType": "custom",
"lessThanOrEqual": "v1.36.4"
},
{
"status": "affected",
"version": "v1.35.0",
"versionType": "custom",
"lessThanOrEqual": "v1.35.8"
},
{
"status": "affected",
"version": "v1.34.0",
"versionType": "custom",
"lessThanOrEqual": "v1.34.11"
},
{
"status": "unknown",
"version": "v1.0",
"versionType": "custom",
"lessThanOrEqual": "v1.33.13"
}
],
"platforms": [
"Windows"
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-09-28T12:17:36.723",
"references": [
{
"url": "https://github.com/kubernetes/kubernetes/issues/141294",
"source": "jordan@liggitt.net"
},
{
"url": "https://github.com/kubernetes/kubernetes/pull/141296",
"source": "jordan@liggitt.net"
},
{
"url": "https://groups.google.com/g/kubernetes-security-announce/c/v_ob5Gf4-eY",
"source": "jordan@liggitt.net"
},
{
"url": "http://www.openwall.com/lists/oss-security/2026/09/28/1",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Awaiting Analysis",
"weaknesses": [
{
"type": "Secondary",
"source": "jordan@liggitt.net",
"description": [
{
"lang": "en",
"value": "CWE-22"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A path traversal vulnerability was discovered in the Kubernetes kubectl client's kubectl cp command on Windows. When copying files from a container, kubectl runs tar inside the container to build a tar archive, transfers it over the network, and unpacks it on the local machine. If the tar binary in the container is malicious, it can execute arbitrary code and emit unexpected output, allowing an attacker who controls container contents to write files to arbitrary paths on the user's local machine when kubectl cp is invoked, limited only by the system permissions of the local user. This issue only affects kubectl clients running on Windows."
}
],
"lastModified": "2026-09-29T21:39:02.570",
"sourceIdentifier": "jordan@liggitt.net"
}