CVE-2026-19444
Received Received - Intake

Path Traversal in Kubernetes kubectl Windows Client

Vulnerability report for CVE-2026-19444, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: Kubernetes

Description

A path traversal vulnerability was discovered in the Kubernetes kubectl client's kubectl cp command on Windows. When copying files from a container, kubectl runs tar inside the container to build a tar archive, transfers it over the network, and unpacks it on the local machine. If the tar binary in the container is malicious, it can execute arbitrary code and emit unexpected output, allowing an attacker who controls container contents to write files to arbitrary paths on the user's local machine when kubectl cp is invoked, limited only by the system permissions of the local user. This issue only affects kubectl clients running on Windows.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
kubernetes kubectl *
kubernetes kubectl From 1.34.0 (inc) to 1.34.11 (inc)
kubernetes kubectl From 1.35.0 (inc) to 1.35.8 (inc)
kubernetes kubectl From 1.36.0 (inc) to 1.36.4 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-19444 is a path traversal vulnerability in the kubectl cp command on Windows. It allows arbitrary file writes when copying files from a container to a local machine. If the container's tar binary is malicious, it can output unexpected results, enabling an attacker to write files to arbitrary paths on the user's Windows machine, limited only by the user's system permissions.

Detection Guidance

This vulnerability only affects Windows systems using kubectl cp with untrusted containers. Detection involves checking kubectl version and usage patterns. Verify if kubectl versions v1.34.0 to v1.34.11, v1.35.0 to v1.35.8, or v1.36.0 to v1.36.4 are installed on Windows systems. Monitor for unexpected file writes or suspicious activity during kubectl cp operations.

Impact Analysis

This vulnerability impacts users running kubectl on Windows who use kubectl cp to copy files from untrusted containers. An attacker controlling the container contents could write files to arbitrary paths on the user's local machine, potentially leading to system compromise or data theft. The impact is limited by the user's system permissions.

Compliance Impact

This vulnerability primarily impacts data integrity and access controls. Arbitrary file writes on a user's machine could lead to unauthorized data exposure or modification, violating GDPR's data protection principles or HIPAA's integrity requirements if sensitive data is involved. The risk depends on whether the affected system handles regulated data.

Mitigation Strategies

Avoid using kubectl cp on Windows to copy files from untrusted containers. Only use kubectl cp with containers from trusted sources. Upgrade kubectl to a patched version if available. If upgrading is not possible, disable kubectl cp usage on Windows systems entirely.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19444. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart