Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-57851

24
FAUCET Score

OVERVIEW CVE-2025-57851 is a container privilege escalation vulnerability affecting Multicluster Engine for Kubernetes images. The flaw stems from the /etc/passwd file being created with group-writable permissions during the container build process, allowing an attacker with container command execution privileges to modify the file and escalate to root access. SEVERITY The vulnerability carries a CVSS 3.1 score of 6.4 (Medium) with a local attack vector requiring high privileges but no user interaction. While the attack complexity is high, successful exploitation grants complete compromise of container confidentiality, integrity, and availability through arbitrary UID assignment, including root-level access (UID 0). An attacker would need existing container execution capabilities, typically gained through compromised applications or legitimate container access. EXPLOITATION STATUS This vulnerability shows minimal exploitation activity and community attention. It is not listed on the CISA KEV (Known Exploited Vulnerabilities) catalog, indicating no confirmed active exploitation in the wild. The EPSS score of 0.00007 places it well below the average CVE, suggesting low real-world exploitation likelihood. No public exploit code appears widely available at this time. The inactive status on exploit tracking lists indicates this remains primarily a theoretical risk requiring specific preconditions for successful exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:redhat:advanced_cluster_management_for_kubernetes:-:*:*:*:*:*:*:*
All Versions ImpactedCPE match
cpe:2.3:a:redhat:multicluster_engine_for_kubernetes:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.4MEDIUM

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
0.5
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.11%
Probability of exploitation in next 30 days
EPSS Percentile
1.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0011 is in the 22nd percentile among its peer group of 3,720 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

redhatvendor investigatingvia nvd_reference
View patch

References

access.redhat.com / security/cve/CVE-2025-57851
Vendor Advisory
bugzilla.redhat.com / show_bug.cgi
Issue TrackingVendor Advisory