TTO-2026-0922-154 · September 22, 2026 VulnerabilityContainer Security

Red Hat OpenShift CVE-2026-88312 Allows Attackers to Bypass PGP Signature Checks and Push Unsigned Container Images

redhat.comCVE-2026-88312 CVSS 8.6OpenShift Container PlatformPGP signature verification bypassUnsigned container image deploymentSupply chain integrity failureNo active exploitation reported

Summary

Red Hat has patched CVE-2026-88312, a high-severity vulnerability in OpenShift Container Platform that allows an attacker with sufficient cluster access to bypass PGP cryptographic signature verification and deploy unsigned or maliciously modified container images to a production OpenShift cluster. The vulnerability is rated CVSS 8.6. Organizations that rely on OpenShift’s image signature policy to enforce container supply chain integrity — ensuring that only images signed by trusted parties can run in the cluster — are exposed to supply chain compromise if the signature check can be bypassed. Red Hat has released patched versions and has not reported active exploitation. The vulnerability was discovered and reported by CrowdStrike.

Timeline

DateEvent
September 2026CrowdStrike researchers discover CVE-2026-88312 PGP signature bypass in OpenShift Container Platform; reported to Red Hat
Sep 21, 2026Red Hat releases patched OpenShift Container Platform versions addressing CVE-2026-88312; CybersecurityNews reports full details
Sep 22, 2026TTO-2026-0922-154 published; no active exploitation reported as of publication

What Happened

OpenShift Container Platform includes a policy enforcement mechanism that can require all container images to carry valid PGP cryptographic signatures from trusted signers before they are permitted to run in the cluster. This mechanism is a supply chain integrity control intended to prevent attackers who have compromised a container registry or who can inject images into the deployment pipeline from deploying malicious containers into production. CVE-2026-88312 is a flaw in the signature verification logic that allows this policy to be bypassed.

An attacker who has compromised a container registry, obtained write access to an image repository, or positioned themselves in the image delivery path can exploit CVE-2026-88312 to deploy unsigned container images — or images signed with an untrusted key — to a cluster whose policy nominally requires trusted signatures. The bypass does not require cluster administrator credentials; it requires the ability to influence the container image that the cluster attempts to pull.

CVE-2026-88312 does not enable remote code execution or privilege escalation on its own. Its impact is that it defeats the cryptographic integrity control that organizations use to enforce “only trusted images run here” as a supply chain security policy. In environments where that policy is the primary defense against container supply chain compromise, the bypass effectively disables that layer of defense. Organizations running OpenShift should update to the patched version immediately and audit recent deployments for unsigned image warnings that may have been suppressed or bypassed.

Domain Intelligence

redhat.com — 62.15

redhat.com scores in the low-trust range at 62.15. Red Hat is the vendor of the affected OpenShift Container Platform product and the party that patched CVE-2026-88312 and published remediation guidance. One threat intelligence source has flagged redhat.com but the observation has not been independently corroborated.

Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 22, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 8, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 7, 2026