CVE-2026-71566
FakeFish handles incoming credentials by passing them down to scripts. This works for real hardware because in the end it's up to the BMC to validate them. However, KubeVirt relies on a KUBECONFIG file mounted to the container and completely ignores the credentials. This allows any user of the cluster to control VMs of the user that created fakefish, power them on and off, and mount arbitrary CD images to them.
Published:Aug 17, 2026
Last Modified:Aug 21, 2026
EPS:Aug 17, 2026
EPSS Score:0.00212
CVSS Score:9.3
Affected Products
Vendor
Product
Action
Vendor
Openshift-metal3
Product
Fakefish
Openshift-metal3
Fakefish
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
