« Back to list

CVE-2026-19444

Status: Awaiting AnalysisMedium (6.5)—

A path traversal vulnerability was discovered in the Kubernetes kubectl client's kubectl cp command on Windows. When copying files from a container, kubectl runs tar inside the container to build a tar archive, transfers it over the network, and unpacks it on the local machine. If the tar binary in the container is malicious, it can execute arbitrary code and emit unexpected output, allowing an attacker who controls container contents to write files to arbitrary paths on the user's local machine when kubectl cp is invoked, limited only by the system permissions of the local user. This issue only affects kubectl clients running on Windows.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

🎯 ATT&CK techniques

How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.

Requiere interacción del usuario (kubectl cp) y control del contenedor. Impacto principal: escritura arbitraria de archivos (T1565.001); secundario: ejecución de código mediante tar malicioso (T1059.003).

Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.

🛡️ ATT&CK mitigations that cover these techniques

Affected technologies (1)

⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2026-19444",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-19444",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-09-28T18:08:52.660901Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "jordan@liggitt.net",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:C/C:L/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 4.7,
        "exploitabilityScore": 1.2
      }
    ]
  },
  "affected": [
    {
      "source": "jordan@liggitt.net",
      "affectedData": [
        {
          "repo": "https://github.com/kubernetes/kubernetes",
          "vendor": "Kubernetes",
          "product": "Kubernetes",
          "versions": [
            {
              "status": "affected",
              "version": "v1.36.0",
              "versionType": "custom",
              "lessThanOrEqual": "v1.36.4"
            },
            {
              "status": "affected",
              "version": "v1.35.0",
              "versionType": "custom",
              "lessThanOrEqual": "v1.35.8"
            },
            {
              "status": "affected",
              "version": "v1.34.0",
              "versionType": "custom",
              "lessThanOrEqual": "v1.34.11"
            },
            {
              "status": "unknown",
              "version": "v1.0",
              "versionType": "custom",
              "lessThanOrEqual": "v1.33.13"
            }
          ],
          "platforms": [
            "Windows"
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-09-28T12:17:36.723",
  "references": [
    {
      "url": "https://github.com/kubernetes/kubernetes/issues/141294",
      "source": "jordan@liggitt.net"
    },
    {
      "url": "https://github.com/kubernetes/kubernetes/pull/141296",
      "source": "jordan@liggitt.net"
    },
    {
      "url": "https://groups.google.com/g/kubernetes-security-announce/c/v_ob5Gf4-eY",
      "source": "jordan@liggitt.net"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2026/09/28/1",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Awaiting Analysis",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "jordan@liggitt.net",
      "description": [
        {
          "lang": "en",
          "value": "CWE-22"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A path traversal vulnerability was discovered in the Kubernetes kubectl client's kubectl cp command on Windows. When copying files from a container, kubectl runs tar inside the container to build a tar archive, transfers it over the network, and unpacks it on the local machine. If the tar binary in the container is malicious, it can execute arbitrary code and emit unexpected output, allowing an attacker who controls container contents to write files to arbitrary paths on the user's local machine when kubectl cp is invoked, limited only by the system permissions of the local user. This issue only affects kubectl clients running on Windows."
    }
  ],
  "lastModified": "2026-09-29T21:39:02.570",
  "sourceIdentifier": "jordan@liggitt.net"
}