CVE-2026-62371: KubeEdge: Command Injection in NodeUpgradeJob - RCE on edge nodes via v1alpha2 API

Published Sep 21, 2026
·
Updated

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.12.0 until 1.21.2, 1.22.2, and 1.23.1, the v1alpha2 NodeUpgradeJob handler in edge/pkg/taskmanager/actions/nodeupgradejob.go concatenates authenticated user-controlled spec.version and spec.image values into the keadm upgrade edge shell command. A user with permission to create or update NodeUpgradeJob resources can supply shell metacharacters in either field, causing arbitrary commands to execute on targeted edge nodes with the privileges of the upgrade process and compromising node confidentiality, integrity, and availability. This issue is fixed in versions 1.21.2, 1.22.2, and 1.23.1.

Affected Software

4 affected components
KubeEdge KubeEdge>1.12.0<=1.21.2
KubeEdge KubeEdge=1.21.2
KubeEdge KubeEdge=1.22.2
KubeEdge KubeEdge=1.23.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 1.21.2
  2. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 1.22.2
  3. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 1.23.1

Event History

Sep 21, 2026
CVE Published
via MITRE·05:02 PM
Data Sourced
via MITRE·05:02 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this vulnerability?

An authenticated user who has permission to create or update v1alpha2 NodeUpgradeJob resources can exploit it. The attacker does not need user interaction and can target edge nodes through a crafted upgrade job.

2

Are default deployments affected?

The issue is reachable through the v1alpha2 NodeUpgradeJob handler, but the provided information does not state whether NodeUpgradeJob creation or update permissions are granted by default. Exposure depends on whether users or service accounts have those permissions and whether they can submit jobs targeting edge nodes.

3

What access does successful exploitation provide?

Injected commands execute on targeted edge nodes with the privileges of the upgrade process. This can compromise the confidentiality, integrity, and availability of those nodes.

4

Which versions should be upgraded?

Upgrade to KubeEdge 1.21.2, 1.22.2, or 1.23.1. Versions from 1.12.0 up to the relevant fixed release are affected.

5

What can be done before patching?

Restrict create and update permissions for v1alpha2 NodeUpgradeJob resources to only fully trusted administrators. Treat spec.version and spec.image values in existing or proposed NodeUpgradeJobs as untrusted, particularly if they contain shell metacharacters.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203