Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-9594

26
FAUCET Score

CVE-2024-9594 is a critical security flaw in Kubernetes Image Builder versions <= v0.1.37, affecting VM images built using Nutanix, OVA, QEMU, or raw providers. During the image build process, default credentials are enabled, allowing an attacker to gain root access to the VM. While these credentials are disabled post-build, an attacker could exploit this vulnerability if they accessed the VM during its creation to modify the image. The vulnerability carries a CVSS score of 8.1 (HIGH), indicating a high severity due to its network-based attack vector, low attack complexity, and potential for complete compromise (confidentiality, integrity, and availability). The FAUCET Risk Score is 65/100, and the CWE is CWE-798 (Use of Hard-coded Credentials). Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, with only one mention and one article, suggesting limited public awareness despite its critical nature.

Impacted Technologies

VendorProductVersion(s)CPE
< 0.1.38CPE matchmatch criteria
cpe:2.3:a:kubernetes-sigs:image_builder:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.1HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.2
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.63%
Probability of exploitation in next 30 days
EPSS Percentile
73.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0163 is in the 31st percentile among its peer group of 8,918 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

check_pointpatch availablevia llm_extracted
View patch
chromepatch availablevia llm_extracted
View patch
github_advisorypatch availablevia nvd_reference
View patch
gopatch availablevia ghsa
Product: github.com/kubernetes-sigs/image-builderFixed in: 0.1.38
infiniflowpatch availablevia llm_extracted
View patch
vuepatch availablevia llm_extracted
View patch

Vendor Advisories (6)

goGHSA-8jpg-62jc-hwhrmedium

VM images built with Image Builder with some providers use default credentials during builds in github.com/kubernetes-sigs/image-builder

Oct 15, 2024
redhatCVE-2024-9594Moderate

kubernetes-image-builder: VM images built with Image Builder with some providers use default credentials during builds

Oct 15, 2024
vuellm-vue-81235edcfc58017f

VM images built with Image Builder with some providers use default credentials during builds

chromellm-chrome-67e21d43252365e6

VM images built with Image Builder with some providers use default credentials during builds

check_pointllm-check_point-0ce6a3a008a1ee91

VM images built with Image Builder with some providers use default credentials during builds

infiniflowllm-infiniflow-f42b6390525ea6c6

VM images built with Image Builder with some providers use default credentials during builds

References

github.com / kubernetes/kubernetes/issues/128007
Issue Tracking
github.com / kubernetes-sigs/image-builder/pull/1596
Patch
groups.google.com / g/kubernetes-security-announce/c/UKJG-oZogfA/m/Lu1hcnHmAQAJ
Vendor Advisory