🔐 CVE Alert

CVE-2026-19444

MEDIUM 6.5

Kubernetes kubectl cp path traversal on Windows allows arbitrary file writes

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

A path traversal vulnerability was discovered in the Kubernetes kubectl client's kubectl cp command on Windows. When copying files from a container, kubectl runs tar inside the container to build a tar archive, transfers it over the network, and unpacks it on the local machine. If the tar binary in the container is malicious, it can execute arbitrary code and emit unexpected output, allowing an attacker who controls container contents to write files to arbitrary paths on the user's local machine when kubectl cp is invoked, limited only by the system permissions of the local user. This issue only affects kubectl clients running on Windows.

CWE CWE-22
Vendor kubernetes
Product kubernetes
Ecosystems
Industries
Technology
Published Sep 28, 2026
Last Updated Sep 28, 2026
Stay Ahead of the Next One

Get instant alerts for kubernetes kubernetes

Be the first to know when new medium vulnerabilities affecting kubernetes kubernetes are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:C/C:L/I:H/A:N
Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
High
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
High
Availability
None

Affected Versions

Kubernetes / Kubernetes
v1.36.0 ≤ v1.36.4 v1.35.0 ≤ v1.35.8 v1.34.0 ≤ v1.34.11

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/kubernetes/kubernetes/issues/141294 github.com: https://github.com/kubernetes/kubernetes/pull/141296 groups.google.com: https://groups.google.com/g/kubernetes-security-announce/c/v_ob5Gf4-eY openwall.com: http://www.openwall.com/lists/oss-security/2026/09/28/1

Credits

🔍 Moriel Harush Vyom Yadav Maciej Szulik Marly Salazar