天下漏洞,尽知其名
HIGH

CVE-2026-86330 NooBaa 操作系统命令注入漏洞

影响认证管理员可注入命令,在主机上以 NooBaa 进程权限执行任意命令

AI 研判

NooBaa 的 cluster_internal_api 中 set_hostname_internal 函数存在操作系统命令注入漏洞。该组件用于管理 OpenShift Data Foundation 中的多云对象网关。由于 hostname 参数未经净化即拼接进 shell 命令,攻击者可借此执行任意系统命令。

影响范围

NooBaa

受影响组件为 NooBaa 的 cluster_internal_api(set_hostname_internal 函数),具体受影响版本范围暂无公开信息。

漏洞详情

漏洞类型为 OS 命令注入(CWE-78)。成因是 set_hostname_internal 将用户可控的 hostname 参数直接传入 shell 命令,未过滤 shell 元字符。具备管理权限的认证攻击者可构造含分号、管道等元字符的 hostname,使命令在主机上以 NooBaa 进程权限执行。

利用条件与风险

利用需先通过认证并拥有管理员权限,属于高权限后利用场景,但一旦成功即可在主机层面执行命令,可能横向影响 OpenShift Data Foundation 集群。

修复建议

官方修复方案暂无公开信息,建议关注 NooBaa/OpenShift Data Foundation 官方安全公告并及时升级;临时缓解可限制管理接口访问、对 hostname 输入做严格校验并避免直接拼接 shell 命令。

原始情报

An OS command injection flaw was found in the set_hostname_internal function of NooBaa’s cluster_internal_api. This component is responsible for managing the Multi-Cloud Object Gateway in OpenShift Data Foundation. The vulnerability occurs because the hostname parameter is passed directly to a shell command without proper sanitization. An authenticated attacker with administrative privileges can provide a specially crafted hostname containing shell metacharacters to execute arbitrary commands on the host system with the privileges of the NooBaa process.