Red HatCVE-2026-71567
Red Hat fakefish: command injection
High7.7CVE-2026-71567 · Published Aug 17, 2026 · updated Sep 1, 2026
In openshift-metal3/fakefish there is a repeated pattern in some of the scripts where shell variables are injected without quoting them either into command lines or into manifests. This mostly applies to the Image URL and BMC credentials (which are not verified by FakeFish).
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| fakefish Product | <= 28f9a6b | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-78
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 17 | Red Hat managedcluster-import-controller: privilege escalation | Critical9.9 | No fix yet |
| Aug 17 | Red Hat Advanced Cluster Management: improper privilege management | High8.8 | No fix yet |
| Aug 17 | Red Hat acm-search-v2-rhel9. This vulnerability: code execution | Critical9.1 | No fix yet |
| Aug 17 | Red Hat multicloud-operators-subscription: privilege escalation | Critical9.9 | No fix yet |
| Aug 17 | Red Hat fakefish: missing authentication | Critical9.3 | No fix yet |
| Aug 17 | Red Hat OpenShift AI (RHOAI): remote code execution | High7.9 | No fix yet |