VDB
CVE-2025-9276
CVE-2025-9276
PUBLISHED
CVSS 9.800000190734863 CRITICAL
Cockroach Labs cockroach-k8s-request-cert Empty Root Password Authentication Bypass Vulnerability. This vulnerability could allow remote attackers to bypass authentication on systems that use the affected version of the Cockroach Labs cockroach-k8s-request-cert container image. The specific flaw exists within the configuration of the system shadow file. The issue results from a blank password setting for the root user. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-22195.
EPSS 0.65% · 49.8th percentile
Risk Scores
CVSS 3.0
9.800000190734863
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.65%
49.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| cockroachlabs | cockroach-k8s-request-cert | |
| Cockroach Labs | cockroach-k8s-request-cert | cockroachdb/cockroach-k8s-request-cert:latest |
Timeline
- Aug 20, 2025 PoC Published
- Sep 2, 2025 CVE Published
- Sep 2, 2025 PoC Published
- Sep 3, 2025 EPSS Score
- Sep 3, 2025 PoC Published
- Sep 3, 2025 CVE Updated
- Sep 11, 2025 EPSS Score
- Sep 19, 2025 EPSS Score
- Sep 27, 2025 EPSS Score
- Oct 5, 2025 EPSS Score
- Oct 13, 2025 EPSS Score
- Oct 21, 2025 EPSS Score