The specific flaw exists within the configuration of the system shadow file. The issue results from a blank password setting for the root user. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-22195.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-26436 | Cockroach Labs cockroach-k8s-request-cert Empty Root Password Authentication Bypass Vulnerability. This vulnerability could allow remote attackers to bypass authentication on systems that use the affected version of the Cockroach Labs cockroach-k8s-request-cert container image. The specific flaw exists within the configuration of the system shadow file. The issue results from a blank password setting for the root user. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-22195. |
| Link | Providers |
|---|---|
| https://www.zerodayinitiative.com/advisories/ZDI-25-855/ |
|
Wed, 28 Jan 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cockroachlabs
Cockroachlabs cockroach-k8s-request-cert |
|
| CPEs | cpe:2.3:a:cockroachlabs:cockroach-k8s-request-cert:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Cockroachlabs
Cockroachlabs cockroach-k8s-request-cert |
Thu, 04 Sep 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cockroach Labs
Cockroach Labs cockroach-k8s-request-cert |
|
| Vendors & Products |
Cockroach Labs
Cockroach Labs cockroach-k8s-request-cert |
Wed, 03 Sep 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 02 Sep 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cockroach Labs cockroach-k8s-request-cert Empty Root Password Authentication Bypass Vulnerability. This vulnerability could allow remote attackers to bypass authentication on systems that use the affected version of the Cockroach Labs cockroach-k8s-request-cert container image. The specific flaw exists within the configuration of the system shadow file. The issue results from a blank password setting for the root user. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-22195. | |
| Title | Cockroach Labs cockroach-k8s-request-cert Empty Root Password Authentication Bypass Vulnerability | |
| Weaknesses | CWE-258 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: zdi
Published:
Updated: 2025-09-03T15:32:42.164Z
Reserved: 2025-08-20T18:14:23.415Z
Link: CVE-2025-9276
Updated: 2025-09-03T15:32:39.119Z
Status : Analyzed
Published: 2025-09-02T20:15:40.407
Modified: 2026-01-30T20:27:48.443
Link: CVE-2025-9276
No data.
OpenCVE Enrichment
Updated: 2025-09-04T13:12:31Z
EUVD