CVE-2025-9276CWE-258

Cockroach Labs cockroach-k8s-request-cert Empty Root Password Authentication Bypass Vulnerability

Critical · published September 2, 2025

CVSS v3.0
9.8
EPSS
1%
Percentile
48.9
In the wild
Unconfirmed
What it is

🚨 A blank root password! That’s the shocking vulnerability behind CVE-2025-9276, letting remote attackers waltz into systems running the Cockroach Labs cockroach-k8s-request-cert container image. 🔥 Think of it like a hotel that forgot to change the master key after check-in — anyone can walk right in without a reservation. This oversight leaves your system exposed to anyone who knows where to look! An attacker can bypass all authentication measures and gain full access to the system, potentially compromising sensitive data or disrupting services. This could lead to absolute chaos, as unauthorized users would have the keys to the kingdom!

Put simply

Think of it like a hotel that forgot to change the master key after check-in — anyone can walk right in without a reservation. This oversight leaves your system exposed to anyone who knows where to look! This vulnerability arises from an empty password setting for the root user within the system's shadow file, allowing attackers to authenticate without any credentials. Essentially, it’s like having an open door that nobody thought to lock.

What to do

An attacker can bypass all authentication measures and gain full access to the system, potentially compromising sensitive data or disrupting services. This could lead to absolute chaos, as unauthorized users would have the keys to the kingdom! To remediate this critical flaw, set a strong, non-empty password for the root user. Additionally, update to the latest container image versions and audit your configurations to prevent unintended access. Don’t wait — act now to secure your systems! You’ve got this! Follow these steps, and you’ll turn that vulnerability into a success story! 🛡️

The record
Technical detail
CVSS v3.0
9.8 · CRITICAL
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00652 · 48.9th percentile
Weakness
CWE-258 · Empty Password in Configuration File
Published
2025-09-02T20:00Z
EPSS history
Timeline
  • 02 SEP 20:00Z
    Cockroach Labs cockroach-k8s-request-cert Empty Root Password Authentication Bypass Vulnerability
    cvelistv5