CVE-2026-32241 is a high-severity command injection vulnerability (CVSS 7.5) in Flannel's experimental Extension backend, affecting versions prior to 0.28.2 in Kubernetes deployments. An attacker with low privileges can exploit this by setting specific Kubernetes Node annotations, leading to root-level arbitrary command execution on all Flannel nodes, despite the high attack complexity. This critical flaw, classified as CWE-77, allows attacker-controlled data to be piped directly to shell commands without validation. There is no evidence of active exploitation or public exploit code, but it has garnered some community discussion. Mitigation involves upgrading to Flannel v0.28.2 or switching to an unaffected backend like vxlan or wireguard.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.28.2CPE matchmatch criteria | cpe:2.3:a:flannel-io:flannel:*:*:*:*:*:kubernetes:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.