CYBERSECURITYTRACKER
TRACKING
Permanent story citation

[kubernetes] CVE-2026-19444: kubectl cp path traversal on Windows allows arbitrary file writes

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 8746

As cited

Copy frozen at (site build).

vulnerabilities

[kubernetes] CVE-2026-19444: kubectl cp path traversal on Windows allows arbitrary file writes

A path traversal vulnerability in Kubernetes kubectl cp command on Windows allows a malicious tar binary in a container to write files to arbitrary paths on a user's local machine, constrained only by the user's file permissions. The issue is assigned CVE-2026-19444 and rated Medium severity with a CVSS score of 6.5.

Why it matters: Kubernetes administrators and developers using kubectl cp on Windows systems need to assess whether they run containers from untrusted sources, as a compromised container could write malicious files to their workstations.

VendorsMicrosoftKubernetes
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary