Red HatCVE-2026-71566
Red Hat fakefish: missing authentication
Critical9.3CVE-2026-71566 · Published Aug 17, 2026 · updated Sep 1, 2026
FakeFish handles incoming credentials by passing them down to scripts. This works for real hardware because in the end it's up to the BMC to validate them. However, KubeVirt relies on a KUBECONFIG file mounted to the container and completely ignores the credentials. This allows any user of the cluster to control VMs of the user that created fakefish, power them on and off, and mount arbitrary CD images to them.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| fakefish Product | <= 28f9a6b | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-306
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 17 | Red Hat managedcluster-import-controller: privilege escalation | Critical9.9 | No fix yet |
| Aug 17 | Red Hat Advanced Cluster Management: improper privilege management | High8.8 | No fix yet |
| Aug 17 | Red Hat acm-search-v2-rhel9. This vulnerability: code execution | Critical9.1 | No fix yet |
| Aug 17 | Red Hat multicloud-operators-subscription: privilege escalation | Critical9.9 | No fix yet |
| Aug 17 | Red Hat fakefish: command injection | High7.7 | No fix yet |
| Aug 17 | Red Hat OpenShift AI (RHOAI): remote code execution | High7.9 | No fix yet |