AI analysis
CVE-2026-19444 is a path traversal flaw (CWE-22) in the Kubernetes kubectl cp command, and it affects only kubectl clients running on Windows. When a user copies files out of a container, kubectl runs tar inside that container, transfers the archive, and unpacks it locally; a malicious tar binary controlled by an attacker who owns the container contents can emit crafted output that writes files to arbitrary paths on the user's machine, limited only by that local user's permissions. Triggering it requires the victim to invoke kubectl cp (user interaction) against a container the attacker already controls, with adjacent-network access and high privileges in the CVSS scoring (6.5 medium; integrity impact is high, confidentiality low, availability unchanged). Windows users of kubectl who copy from untrusted containers are the affected population; Linux and macOS clients are not affected. There is no known public proof of concept and the CVE is not listed in CISA KEV, so exploitation is none known.
What to do: Upgrade Windows kubectl to the patched release published by the Kubernetes project for CVE-2026-19444; the advisory data does not list fixed version numbers, so confirm the fix against the official Kubernetes release notes before deploying. Until then, do not run kubectl cp against containers or images you do not fully trust, and run the client as a least-privilege local user so a malicious archive cannot write outside that account's permissions.
Estimated exposure
largeon the order of 100,000–1,000,000 Windows kubectl installations (estimate, not a published count) — No install count or internet scan is in the advisory; the estimate is inferred from kubectl being the standard client for widely deployed Kubernetes, with Windows as a common admin workstation OS, narrowed because only Windows clients and…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
A path traversal vulnerability was discovered in the Kubernetes kubectl client's kubectl cp command on Windows. When copying files from a container, kubectl runs tar inside the container to build a tar archive, transfers it over the network, and unpacks it on the local machine. If the tar binary in the container is malicious, it can execute arbitrary code and emit unexpected output, allowing an attacker who controls container contents to write files to arbitrary paths on the user's local machine when kubectl cp is invoked, limited only by the system permissions of the local user. This issue only affects kubectl clients running on Windows.