Skip to content
Rota Nacional

Cyber ·

CVE-2026-19444: kubectl cp risk on Windows

A September 28, 2026, oss-sec feed post describes a medium-severity Kubernetes issue: a malicious tar in a container can cause kubectl cp to write files to arbitrary paths on Windows, within the local user's permissions.

The post reports CVE-2026-19444, classified as medium with a CVSS score of 6.5. The described scenario involves a malicious tar binary inside a container and someone running kubectl cp on Windows; writes may reach arbitrary paths but remain limited by that local account's permissions.

The text was posted to the oss-sec feed on September 28, 2026, and is attributed to Vyom Yadav. The supplied content is an automated translation and ends before giving a complete answer to “Am I vulnerable?”. It does not state affected versions, fixes, or specific mitigations.

To assess exposure, consult the original oss-sec feed post and official Kubernetes advisories, checking affected versions, fixes, and current guidance before taking action. The CVSS score and severity here are those reported by the post; verify them against primary sources.

Until the scope is confirmed, avoid running kubectl cp on Windows with untrusted containers or tar files. If using AI to study the issue, do not include credentials, sensitive configurations, logs containing personal data, or unnecessary internal details; review submitted material and your organization's policy as well.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 5,00.

Try free