it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
[IT-SecNots] [Security-news] Cloud - Critical - Remote code execution - SA-CONTRIB-2026-176
Chronologisch Thread
- From: security-news AT drupal.org
- To: security-news AT drupal.org
- Subject: [IT-SecNots] [Security-news] Cloud - Critical - Remote code execution - SA-CONTRIB-2026-176
- Date: Wed, 23 Sep 2026 16:50:16 +0000
- Arc-authentication-results: i=2; smtp2.osuosl.org; arc=fail smtp.remote-ip=140.211.10.49
- Arc-authentication-results: i=1; smtp1.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=ZoGFK8kS; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b="tD3Yoa7/"; arc=none smtp.remote-ip=54.240.27.34
- Arc-filter: OpenARC Filter v1.3.0 smtp2.osuosl.org DDE1240DF2
- Arc-filter: OpenARC Filter v1.3.0 smtp1.osuosl.org 53D7580F48
- Arc-message-signature: i=2; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1790186226; h=X-Comment:DKIM-Signature:Received:X-Spam-Flag:X-Spam-Score: X-Spam-Level:X-Spam-Status:ARC-Filter:Received-SPF:DKIM-Signature: DKIM-Signature:Date:To:MIME-Version:Feedback-ID:X-Mailman-Rule-Hits: X-Mailman-Rule-Misses:Message-ID-Hash:X-Mailman-Approved-At: Message-ID:From:X-Mailman-Version:Precedence:Reply-To:Subject:List-Id: Archived-At:List-Archive:List-Help:List-Owner:List-Post: List-Subscribe:List-Unsubscribe:Content-Type: Content-Transfer-Encoding; bh=Ol19sFx5vtrOrk+08dZj6koISlRZa53IeAT1YHoCtmw=; b=q6xltk3zQ8pCsYjfH2tLLERfEDC4fbEEWm/v8EBCJXm0KXS/s/9l3NzU4rZuQno4DtCa KF5bdbKBqkYG0q3YnKbPpv9L0CEZYs4QVKVYregz7NiIO2uXluSpDRcnbd3BR+/+0tDlw 0uZKGGdwWEM2r+X9MrcHPlMASdLrL07hjpBeYT1MA5sApoq78ekuiVthNSpTuSfIIhnXJ 0kSO6RMwbVhCtPZJ321WXAxsCy60kDzD1kYbkFYKNzmmMeqm+F4usmJNmeR5pO6H7/GIm fqrakkefZb37plqQtWtEl4jjM2v8kCmblCiYKv6qLlgHP6vGmNLJUY5U1gmaS35iq8w==
- Arc-message-signature: i=1; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1790182217; h=Received-SPF:DKIM-Signature:DKIM-Signature:Date:Message-ID:To: Subject:X-PHP-Originating-Script:MIME-Version:Content-Type: Content-Transfer-Encoding:X-Mailer:Sender:From:Feedback-ID: X-SES-Outgoing; bh=ZVCVk/3CtLzZCClDQbFy3G1g+Ru8Ih/gH0l+Y5aimwY=; b=CVinP+iGaZQkHXLV1sEB0WpNqMOrvjFVQyJS7bbv36Zh4VZV98Ww6zMmTZoWodZHQ/b7 JdfqwlUv8IPj8TkwkH05pAJ3Ju9YkYeSUaGpxcMTd/MszkOp7CTnlkRjfhPm2j32yeAQK g2BRETyWmTMnm3kfKtxV7+4g9Y83bC+eW3izPQJl+zDw5D6h5+VxR7Kes0OT6QYrwzDes ZmR7JEdfPIaXNGjdhlW8dqqxdpXDEUkW+ImJOEyZsqXuKnApa6uBbB2BcXwvXAy0sluMN 5cSrgauCnBxMVon42bvqamtd1YyXUFIR7Vo7fggk9TiNR5JpJNH7QRzI3y+MKgTjx7g==
- Arc-seal: i=2; d=osuosl.org; s=arc; a=rsa-sha256; cv=fail; t=1790186226; b=IwKW7TNQWFQwD8jRSwB7enJnMgDXiZ6rw2Q9vCiFbeRay/qb4zsATywn6Fb6lmo2HIBV R73BYOg89uaKQ7zXanW99dUmDJYjmEShgFIHvu+uwrz5MrI9TIX0MBs5zChG81ychNCV+ EsRwGGR4xs1RNMAkWezqFPYj2daU2o6Odl2R5NuE9AXlkqWIeGxbPKW998KoHGiZpNLWG 1GFzqh+JvcbfJF7DqSgKliWD0VXwIsqfR0YEthS1gL5KZNjUejidyd/MTibpsb4uEgaXH MsQGm36LBmRjBi8mhEDJiS6MN/WCNQhD8IlIoLsfnDFJTJwWm4iQDk4qolBzIbT8/bQ==
- Arc-seal: i=1; d=osuosl.org; s=arc; a=rsa-sha256; cv=none; t=1790182217; b=Nz+fof1rugwwAOCejdZa3hEez99d3r5oCyu2K5SNPXtUqZBxMZP5uXsUYhJbGIiDLKKv hvjMRCB/HNOxqedTCth8T5VtuxvxD5RRRqqUJNhSSaEAKcC9lUuWi/KyDe5GW5glZl+GU UtuQuLhpFyPsvXbvSnZY/gqjLZbEQr784Rfl2TWoUWQofrMK8MHl2c35cU6vbxF3HCTlc IYj1Ih575AIXYxoG2sd7fJh28gRHw+BjumUkHZlTJIHtQzOaMRJyCLo8DaPSOjKqw3+7Y S4k3QwtbqQJvEKKIeLsVMsOlBadQOyNFNrdALhfJKfUmdKm5eSFLAV7jy4Q+FTRwpNw==
- Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/2QEJYF7DUX6SBYJRD4DIPSAIT5L22VQT/>
- Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b=DuaMxzp3; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=ZoGFK8kS; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b="tD3Yoa7/"; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 140.211.166.133 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org; arc=reject ("cv is fail on i=2"); dmarc=pass (policy=none) header.from=drupal.org
- Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
- List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
- List-id: <security-news.drupal.org>
View online: https://www.drupal.org/sa-contrib-2026-176
Project: Cloud [1]
Project machine name: cloud
Date: 2026-September-23
Security risk: *Critical* 15 ∕ 25
AC:Complex/A:None/CI:Some/II:Some/E:Theoretical/TD:All [2]
Vulnerability: Remote code execution
Affected versions: <7.0.1
CVE IDs: CVE-2026-96375
Description:
The Cloud module enables users to manage cloud infrastructure through Drupal.
The Kubernetes and VMware integrations do not properly validate TLS
certificates when connecting to remote API endpoints. An attacker who can
intercept these connections may obtain secret tokens or other credentials,
potentially allowing unauthorized access to the connected infrastructure.
Solution:
If you use Cloud, install the latest version and configure certificates
appropriately:
* If you use the 7.0.0 branch, update to 7.0.1 [3].
The update enables TLS certificate verification for Kubernetes and VMware
connections. Sites using a private certificate authority must configure the
CA certificate path for the affected connection or ensure that the issuing CA
is trusted by the PHP runtime. Run the Drupal database updates and rebuild
caches after upgrading.
Reported By:
* Kalle Kipinä (kekkis) [4]
Fixed By:
* AI Yas (ai_yas) [5]
* baldwinlouie [6]
* Yas Naoi (yas) [7]
Coordinated By:
* Swan Kalata (akalata) [8] of the Drupal Security Team
* Greg Knaddison (greggles) [9] of the Drupal Security Team
* Juraj Nemec (poker10) [10] of the Drupal Security Team
* Jess (xjm) [11] of the Drupal Security Team
------------------------------------------------------------------------------
Contribution record [12]
[1] https://www.drupal.org/project/cloud
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/cloud/releases/7.0.1
[4] https://www.drupal.org/u/kekkis
[5] https://www.drupal.org/u/ai_yas
[6] https://www.drupal.org/u/baldwinlouie
[7] https://www.drupal.org/u/yas
[8] https://www.drupal.org/u/akalata
[9] https://www.drupal.org/u/greggles
[10] https://www.drupal.org/u/poker10
[11] https://www.drupal.org/u/xjm
[12] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3622599
_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at
- [IT-SecNots] [Security-news] Cloud - Critical - Remote code execution - SA-CONTRIB-2026-176, security-news, 23.09.2026
Archiv bereitgestellt durch MHonArc 2.6.19+.