CVE-2026-86330 NooBaa 操作系统命令注入漏洞
影响认证管理员可注入命令,在主机上以 NooBaa 进程权限执行任意命令
NooBaa 的 cluster_internal_api 中 set_hostname_internal 函数存在操作系统命令注入漏洞。该组件用于管理 OpenShift Data Foundation 中的多云对象网关。由于 hostname 参数未经净化即拼接进 shell 命令,攻击者可借此执行任意系统命令。
影响范围
受影响组件为 NooBaa 的 cluster_internal_api(set_hostname_internal 函数),具体受影响版本范围暂无公开信息。
漏洞详情
漏洞类型为 OS 命令注入(CWE-78)。成因是 set_hostname_internal 将用户可控的 hostname 参数直接传入 shell 命令,未过滤 shell 元字符。具备管理权限的认证攻击者可构造含分号、管道等元字符的 hostname,使命令在主机上以 NooBaa 进程权限执行。
利用条件与风险
利用需先通过认证并拥有管理员权限,属于高权限后利用场景,但一旦成功即可在主机层面执行命令,可能横向影响 OpenShift Data Foundation 集群。
修复建议
官方修复方案暂无公开信息,建议关注 NooBaa/OpenShift Data Foundation 官方安全公告并及时升级;临时缓解可限制管理接口访问、对 hostname 输入做严格校验并避免直接拼接 shell 命令。
An OS command injection flaw was found in the set_hostname_internal function of NooBaa’s cluster_internal_api. This component is responsible for managing the Multi-Cloud Object Gateway in OpenShift Data Foundation. The vulnerability occurs because the hostname parameter is passed directly to a shell command without proper sanitization. An authenticated attacker with administrative privileges can provide a specially crafted hostname containing shell metacharacters to execute arbitrary commands on the host system with the privileges of the NooBaa process.