CVE Explorer
CVE-2026-44543
Local Path Provisioner provides a way for the Kubernetes users to utilize the local storage in each node. Prior to 0.0.36, a malicious user with permission to edit the local-path-config ConfigMap in the local-path-storage namespace can manipulate the helperPod.yaml template used by rancher/local-path-provisioner. The helperPod.yaml template is loaded by the provisioner and used to create HelperPods during PVC provisioning and cleanup operations. However, the template is not sufficiently validate
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"local-path-provisioner","vendor":"rancher","versions":[{"status":"affected","version":"< 0.0.36"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:234e3f580cb71e302e9822fafc9171faf9d18ed812f861da8c01a793faa973f0 · sha256:2f559670c6402dd7… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":8.7,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"HIGH","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:234e3f580cb71e302e9822fafc9171faf9d18ed812f861da8c01a793faa973f0 · sha256:2f559670c6402dd7… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-269","description":"CWE-269: Improper Privilege Management","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:234e3f580cb71e302e9822fafc9171faf9d18ed812f861da8c01a793faa973f0 · sha256:2f559670c6402dd7… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"name":"https://github.com/rancher/local-path-provisioner/security/advisories/GHSA-7fxv-8wr2-mfc4","tags":["x_refsource_CONFIRM"],"url":"https://github.com/rancher/local-path-provisioner/security/advisories/GHSA-7fxv-8wr2-mfc4"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:234e3f580cb71e302e9822fafc9171faf9d18ed812f861da8c01a793faa973f0 · sha256:2f559670c6402dd7… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.