CVE-2026-29955 is a command injection vulnerability in the kubeconfiggenerator component of KubePlus versions 4.14, specifically in the /registercrd endpoint. The flaw exists because the component uses subprocess.Popen() with shell=True while directly concatenating unsanitized user input from the chartName parameter into shell commands, allowing attackers to inject and execute arbitrary commands. The vulnerability carries a CVSS score of 8.8 (HIGH) with a network-based attack vector requiring only low privileges and no user interaction. Successful exploitation would result in high-impact compromises across confidentiality, integrity, and availability of the affected system. The EPSS score of 0.00088 indicates relatively low predicted exploitation probability compared to the broader CVE landscape. There is currently no evidence of active exploitation, as the vulnerability does not appear on the Known Exploited Vulnerabilities (KEV) catalog and is marked as inactive on threat tracking lists. However, organizations running KubePlus 4.14 should prioritize patching given the ease of exploitation and severe potential impact, particularly in environments where the kubeconfiggenerator component is exposed to authenticated users.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.2.0CPE matchmatch criteria | cpe:2.3:a:cloudark:kubeplus:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.