CVE-2026-76654

Public on 2026-09-25
Modified on 2026-09-25
Description
An NTLM coercion vulnerability exists on Windows nodes when the subPath supplied in a pod's volumeMounts is set to a symbolic link that points to an attacker-controlled network share. When a kubelet resolves symlinks, it does not reject a target that resolves to a UNC path. As a result, the kubelet will transparently attempt to authenticate to the share using NTLM.

This allows an attacker to obtain the NetNTLMv2 hash of the account under which the kubelet is running. An attacker could then attempt to crack the hash to retrieve the corresponding password or relay it to impersonate the node, if the node is domain-joined.
Severity
Medium severity
Medium
See what this means
CVSS v3 Base Score
5.8
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Aws-nitro-enclaves-cli Extra containerd Not Affected
Amazon Linux 2 - Docker Extra containerd Not Affected
Amazon Linux 2 - Ecs Extra containerd Not Affected
Amazon Linux 2023 containerd Not Affected
Amazon Linux 2027 Preview containerd Not Affected
Amazon Linux 2 - Core cri-tools Not Affected

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 5.8 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N