# CVE-2026-19444

Publisher-attributed story with a reviewed brief or permitted publisher paragraph. The original publisher is responsible for the linked reporting.

- Publisher: Kubernetes
- Category: Vulnerabilities
- Original publication time: 2026-08-10T14:49:49Z
- First observed by NexusTechWire: 2026-10-01T20:28:38Z
- Original source: https://github.com/kubernetes/kubernetes/issues/141294
- NexusTechWire record: https://nexustechwire.com/news/news-245d159d562c1a547851

## The brief

Kubernetes has disclosed CVE-2026-19444, a medium-severity vulnerability in kubectl's Windows file-copy function. Copying data from a container an operator does not control can allow unauthorized writes on their computer within their existing permissions. The advisory lists fixes in releases 1.34.12, 1.35.9 and 1.36.5, and recommends avoiding copies from untrusted containers before upgrading. Only Windows clients are affected.

AI-assisted NexusTechWire summary, checked against the linked source on 2026-10-01T23:11:41Z. Not independent reporting.

Source license: [CC BY 4.0](https://creativecommons.org/licenses/by/4.0/). Source material adapted into an original NexusTechWire brief. Original source license applies.

Read the full original: [Kubernetes](https://github.com/kubernetes/kubernetes/issues/141294)

This record does not reproduce the complete article or represent independent confirmation of every source claim.
