Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [Security-news] Cloud - Critical - Remote code execution - SA-CONTRIB-2026-177

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [Security-news] Cloud - Critical - Remote code execution - SA-CONTRIB-2026-177


Chronologisch Thread  
  • From: security-news AT drupal.org
  • To: security-news AT drupal.org
  • Subject: [IT-SecNots] [Security-news] Cloud - Critical - Remote code execution - SA-CONTRIB-2026-177
  • Date: Wed, 23 Sep 2026 16:51:10 +0000
  • Arc-authentication-results: i=2; smtp2.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=I22LI37m; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=fK+2gdsk; arc=fail smtp.remote-ip=140.211.10.49
  • Arc-authentication-results: i=1; smtp2.osuosl.org; dmarc=pass header.from=drupal.org; dkim=pass header.d=drupal.org header.i= AT drupal.org header.a=rsa-sha256 header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=I22LI37m; dkim=pass header.d=amazonses.com header.i= AT amazonses.com header.a=rsa-sha256 header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=fK+2gdsk; arc=none smtp.remote-ip=54.240.27.34
  • Arc-filter: OpenARC Filter v1.3.0 smtp2.osuosl.org 12EA143503
  • Arc-filter: OpenARC Filter v1.3.0 smtp2.osuosl.org AAC18403B0
  • Arc-message-signature: i=2; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1790186297; h=X-Comment:DKIM-Signature:Received:X-Spam-Flag:X-Spam-Score: X-Spam-Level:X-Spam-Status:ARC-Filter:Received-SPF:DKIM-Signature: DKIM-Signature:Date:To:MIME-Version:Feedback-ID:X-Mailman-Rule-Hits: X-Mailman-Rule-Misses:Message-ID-Hash:X-Mailman-Approved-At: Message-ID:From:X-Mailman-Version:Precedence:Reply-To:Subject:List-Id: Archived-At:List-Archive:List-Help:List-Owner:List-Post: List-Subscribe:List-Unsubscribe:Content-Type: Content-Transfer-Encoding; bh=F4WTjVZMgPJhocDzhKMY7tmkCLb08C6uAq6fiDLhzuM=; b=n2DqjIDiSybhwYcZSvrRDIOcFyOs2ue9KpUPVBKxBg2fK0H78OwgHTIflg+zEuKhKiku rLu2wZ0k7kIVsmv/d7sRoOb29WolG9FCSJxiH7WXdxqdMBqOWCwg9ZV7zOBHv6og0tKFw Q3uyOj0yLOpOId0jTrWdLjKVad/rNcxStP1S5HmaHOFCIJigipuaGlYYPUoldCK28j+sZ ZPB/O/SS/Wot4bNN/QGpc//cDjOepemgewaHfMd1gn8D554oJxF2EGXl4jQrQl0Z9yPWN ZVzX9f+Tm5mpN3xrbIglwrXxtHWntRyLk3MpzmpepJ4cPN+3qU8/k52iqqjCalQ/Pww==
  • Arc-message-signature: i=1; d=osuosl.org; s=arc; a=rsa-sha256; c=relaxed/relaxed; t=1790182272; h=Received-SPF:DKIM-Signature:DKIM-Signature:Date:Message-ID:To: Subject:X-PHP-Originating-Script:MIME-Version:Content-Type: Content-Transfer-Encoding:X-Mailer:Sender:From:Feedback-ID: X-SES-Outgoing; bh=3+cUtW0hqj5xKq4xxRxtumpa53wKfodUG0iwz46Pq6o=; b=LPwEgAlailA/BcVAAEuBU0MXro+qvJfkrIGLMNvR4GwbUN+c+iSy4VGVVtEBJ2vigwrG xDP+EqHSp2QkhTdsQ22tLTPbAhZHnK0bm/EeNhUVO//6JbN7FGGbFEnuNktZtkJGVZAHU 5gAQX7A39mSBZRNV72ESKoIskj0qGYWHWgTOPYmDkglJjxfdp26oWEk7ea0Hi8XivKCst R62RCjh3PaYnkQ2JuniY2QXkjbc0r193Ny9CgR+hf+un+lEBZx2vvcYfKpeurVqrWiBtt o6NMt96Bo6at9cdf2oImvouob+Q8q3jh32HUihmNr26MRCnwYFjbEUpdnp0ca7nvzDQ==
  • Arc-seal: i=2; d=osuosl.org; s=arc; a=rsa-sha256; cv=fail; t=1790186297; b=kTLss4MQMnezngQHJlb9GVf4ua1woL79Ss5+cH6p1JscT8yT21iB9bkHhg601D866dLu ufrnjtS7hGbrYDAVAfW1KIeIezcbwNMrgTTEuzDxtS0Nu/K8IyRMpaZnqxGauUjU2hgsO oxt5Py7UGUzj4zy7ojs68REpvH7XkQc+/hKfjBgp1Q2jS/VYdT6f70LTy5wlkCAlUwyiP rgU1yy5KxMAsuVgjkW1srug1A/hNa6zCsS4TUu21II/1EDonnJbE8SOpYRSXLM8x4whxZ aUIWNGvY5eCyk2/fpAIidE9N/Mt3UBt5AWj7etfdI/skceKzvDMJEkqEHC1PJV3krlQ==
  • Arc-seal: i=1; d=osuosl.org; s=arc; a=rsa-sha256; cv=none; t=1790182272; b=Pna9HALpbN54d8LoVfYCQHUJem9AZdYjytTpOnPubBnDhokzQelaKcSkcAg9YMxLEEp3 Bcb3JBSzN1BhaQuQ//Ka9LIW2Ys5TMGRQm04fjzxLFlBn+km2MYWLFiyw8X+DgP/AIuQH ZxeJIuXNMtGQtY+frC8llA4eBB+rTjp6W0wYOKqjysBJlvE3A7tJgycCkHNHyX1TCvoXW 1d1enntzIt79c7hzQaeklDX5KkX0j5/AzihXUwhHdFRYEp7asCQtW5H/GNzwN2LamfPtA vVJzuL4waRfas0nyaq8grkVkYTQw/m/9CDtIwQEKwuptQATjwr06+r66G2IAmDBwysg==
  • Archived-at: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/message/5C3462C4B2SB7P34KH4AUCXLJD55NFXV/>
  • Authentication-results: lists.piratenpartei.de; dkim=pass header.d=drupal.org header.s=default header.b=T2ytI2u0; dkim=fail ("body hash did not verify") header.d=drupal.org header.s=h2cwj55irf2bug4gly7tdskg3xbjhlg6 header.b=I22LI37m; dkim=fail ("body hash did not verify") header.d=amazonses.com header.s=hsbnp7p3ensaochzwyq5wwmceodymuwv header.b=fK+2gdsk; spf=pass (lists.piratenpartei.de: domain of security-news-bounces AT drupal.org designates 140.211.166.133 as permitted sender) smtp.mailfrom=security-news-bounces AT drupal.org; arc=reject ("cv is fail on i=2"); dmarc=pass (policy=none) header.from=drupal.org
  • Feedback-id: ::1.us-west-2.eaokZ1GT8utLqfMHQoyOsEFVrSIzzS6R+14LP6WIIUY=:AmazonSES
  • List-archive: <https://lists.drupal.org/mailman3/hyperkitty/list/security-news AT drupal.org/>
  • List-id: <security-news.drupal.org>

View online: https://www.drupal.org/sa-contrib-2026-177

Project: Cloud [1]
Project machine name: cloud
Date: 2026-September-23
Security risk: *Critical* 15 ∕ 25
AC:Basic/A:Admin/CI:All/II:All/E:Theoretical/TD:Uncommon [2]
Vulnerability: Remote code execution

Affected versions: <7.0.1
CVE IDs: CVE-2026-96376
Description: 
The Cloud module enables users to manage cloud resources through Drupal.

The module does not sufficiently sanitize user-controlled Git branch and
repository URL values before passing them to shell commands in the Kubernetes
integration. This vulnerability allows an attacker to execute arbitrary
operating-system commands as the web-server user.

This vulnerability is mitigated by the fact that the Kubernetes submodule
must be enabled and configured, Git must be available on the server, and an
attacker must have permission to add or edit cloud server templates.
Exploiting the clone path additionally requires the "launch cloud server
template" permission, or the "launch approved cloud server template"
permission when using the approved-template flow.

Solution: 
Install the latest version:

* If you use Cloud 7.x, upgrade to Cloud 7.0.1 [3].

Reported By: 
* Drew Webber (mcdruid) [4] of the Drupal Security Team

Fixed By: 
* AI Yas (ai_yas) [5]
* Drew Webber (mcdruid) [6] of the Drupal Security Team
* Yas Naoi (yas) [7]

Coordinated By: 
* Swan Kalata (akalata) [8] of the Drupal Security Team
* Greg Knaddison (greggles) [9] of the Drupal Security Team
* Juraj Nemec (poker10) [10] of the Drupal Security Team

------------------------------------------------------------------------------
Contribution record [11]

[1] https://www.drupal.org/project/cloud
[2] https://www.drupal.org/security-team/risk-levels
[3] https://www.drupal.org/project/cloud/releases/7.0.1
[4] https://www.drupal.org/u/mcdruid
[5] https://www.drupal.org/u/ai_yas
[6] https://www.drupal.org/u/mcdruid
[7] https://www.drupal.org/u/yas
[8] https://www.drupal.org/u/akalata
[9] https://www.drupal.org/u/greggles
[10] https://www.drupal.org/u/poker10
[11] https://new.drupal.org/contribution-record?source_link=https%3A//www.drupal.org/node/3624867

_______________________________________________
Security-news mailing list -- security-news AT drupal.org
To unsubscribe send an email to security-news-leave AT drupal.org
Unsubscribe at

  • [IT-SecNots] [Security-news] Cloud - Critical - Remote code execution - SA-CONTRIB-2026-177, security-news, 23.09.2026

Archiv bereitgestellt durch MHonArc 2.6.19+.

Seitenanfang