Summary
Red Hat has patched CVE-2026-88312, a high-severity vulnerability in OpenShift Container Platform that allows an attacker with sufficient cluster access to bypass PGP cryptographic signature verification and deploy unsigned or maliciously modified container images to a production OpenShift cluster. The vulnerability is rated CVSS 8.6. Organizations that rely on OpenShift’s image signature policy to enforce container supply chain integrity — ensuring that only images signed by trusted parties can run in the cluster — are exposed to supply chain compromise if the signature check can be bypassed. Red Hat has released patched versions and has not reported active exploitation. The vulnerability was discovered and reported by CrowdStrike.
Timeline
| Date | Event |
|---|---|
| September 2026 | CrowdStrike researchers discover CVE-2026-88312 PGP signature bypass in OpenShift Container Platform; reported to Red Hat |
| Sep 21, 2026 | Red Hat releases patched OpenShift Container Platform versions addressing CVE-2026-88312; CybersecurityNews reports full details |
| Sep 22, 2026 | TTO-2026-0922-154 published; no active exploitation reported as of publication |
What Happened
OpenShift Container Platform includes a policy enforcement mechanism that can require all container images to carry valid PGP cryptographic signatures from trusted signers before they are permitted to run in the cluster. This mechanism is a supply chain integrity control intended to prevent attackers who have compromised a container registry or who can inject images into the deployment pipeline from deploying malicious containers into production. CVE-2026-88312 is a flaw in the signature verification logic that allows this policy to be bypassed.
An attacker who has compromised a container registry, obtained write access to an image repository, or positioned themselves in the image delivery path can exploit CVE-2026-88312 to deploy unsigned container images — or images signed with an untrusted key — to a cluster whose policy nominally requires trusted signatures. The bypass does not require cluster administrator credentials; it requires the ability to influence the container image that the cluster attempts to pull.
CVE-2026-88312 does not enable remote code execution or privilege escalation on its own. Its impact is that it defeats the cryptographic integrity control that organizations use to enforce “only trusted images run here” as a supply chain security policy. In environments where that policy is the primary defense against container supply chain compromise, the bypass effectively disables that layer of defense. Organizations running OpenShift should update to the patched version immediately and audit recent deployments for unsigned image warnings that may have been suppressed or bypassed.
Domain Intelligence
redhat.com — 62.15
redhat.com scores in the low-trust range at 62.15. Red Hat is the vendor of the affected OpenShift Container Platform product and the party that patched CVE-2026-88312 and published remediation guidance. One threat intelligence source has flagged redhat.com but the observation has not been independently corroborated.
The Trust Observatory · thetrustobservatory.com · September 22, 2026
The Trust Observatory · thetrustobservatory.com · September 8, 2026