CVE-2026-62182

high

Description

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.21.0 until 1.21.2, 1.22.2, and 1.23.1, ConfigUpdateJob processing in edge/pkg/taskmanager/actions/configupdatejob.go concatenates authenticated user-controlled updateFields values into the keadm config-update command and executes it through a system shell. A user with permission to create or modify ConfigUpdateJob resources can include shell metacharacters in the complete --set value and cause arbitrary commands to execute on an enrolled target edge node with the privileges of the KubeEdge process handling the job. This issue is fixed in versions 1.21.2, 1.22.2, and 1.23.1.

References

https://github.com/kubeedge/kubeedge/security/advisories/GHSA-m3c6-2p7h-cfr3

https://github.com/kubeedge/kubeedge/releases/tag/v1.23.1

https://github.com/kubeedge/kubeedge/releases/tag/v1.22.2

https://github.com/kubeedge/kubeedge/releases/tag/v1.21.2

https://github.com/kubeedge/kubeedge/pull/7030

https://github.com/kubeedge/kubeedge/pull/7029

https://github.com/kubeedge/kubeedge/pull/7028

https://github.com/kubeedge/kubeedge/commit/ee78415a36911c1a93e59a921c23b8e4ecd83e90

https://github.com/kubeedge/kubeedge/commit/6309a335c8e5e3c154b6bb0a09292f5c7dc598dc

https://github.com/kubeedge/kubeedge/commit/14f65fc6207787f266cbcb0dceac7f09a81bab2b

https://github.com/kubeedge/kubeedge/blob/master/CHANGELOG/CHANGELOG-1.23.md

https://github.com/kubeedge/kubeedge/blob/master/CHANGELOG/CHANGELOG-1.22.md

https://github.com/kubeedge/kubeedge/blob/master/CHANGELOG/CHANGELOG-1.21.md

Details

Source: Mitre, NVD

Published: 2026-09-21

Updated: 2026-09-24

Risk Information

CVSS v2

Base Score: 9

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 8.8

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.00476