CVE-2025-9276: Cockroachlabs Cockroach-k8s-Request-Cert

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Cockroach Labs cockroach-k8s-request-cert Empty Root Password Authentication Bypass Vulnerability. This vulnerability could allow remote attackers to bypass authentication on systems that use the affected version of the Cockroach Labs cockroach-k8s-request-cert container image. The specific flaw exists within the configuration of the system shadow file. The issue results from a blank password setting for the root user. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-22195.

Affected products

  • Cockroachlabs Cockroach-k8s-Request-Cert: affected versions not specified

Published 2025-09-02. Last modified 2026-06-17.