CVE-2026-76654
Public on 2026-09-25
Modified on 2026-09-25
Description
An NTLM coercion vulnerability exists on Windows nodes when the subPath supplied in a pod's volumeMounts is set to a symbolic link that points to an attacker-controlled network share. When a kubelet resolves symlinks, it does not reject a target that resolves to a UNC path. As a result, the kubelet will transparently attempt to authenticate to the share using NTLM.
This allows an attacker to obtain the NetNTLMv2 hash of the account under which the kubelet is running. An attacker could then attempt to crack the hash to retrieve the corresponding password or relay it to impersonate the node, if the node is domain-joined.
This allows an attacker to obtain the NetNTLMv2 hash of the account under which the kubelet is running. An attacker could then attempt to crack the hash to retrieve the corresponding password or relay it to impersonate the node, if the node is domain-joined.
Severity
See what this means
CVSS v3 Base Score
See breakdown
Affected Packages
| Platform | Package | Release Date | Advisory | Status |
|---|---|---|---|---|
| Amazon Linux 2 - Aws-nitro-enclaves-cli Extra | containerd | Not Affected | ||
| Amazon Linux 2 - Docker Extra | containerd | Not Affected | ||
| Amazon Linux 2 - Ecs Extra | containerd | Not Affected | ||
| Amazon Linux 2023 | containerd | Not Affected | ||
| Amazon Linux 2027 Preview | containerd | Not Affected | ||
| Amazon Linux 2 - Core | cri-tools | Not Affected |
CVSS Scores
| Score Type | Score | Vector | |
|---|---|---|---|
| Amazon Linux | CVSSv3 | 5.8 | CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N |