CVE Vulnerabilities

CVE-2025-9276

Empty Password in Configuration File

Published: Sep 02, 2025 | Modified: Jan 28, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Cockroach Labs cockroach-k8s-request-cert Empty Root Password Authentication Bypass Vulnerability. This vulnerability could allow remote attackers to bypass authentication on systems that use the affected version of the Cockroach Labs cockroach-k8s-request-cert container image.

The specific flaw exists within the configuration of the system shadow file. The issue results from a blank password setting for the root user. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-22195.

Weakness

Using an empty string as a password is insecure.

Affected Software

NameVendorStart VersionEnd Version
Cockroach-k8s-request-certCockroachlabs- (including)- (including)

Potential Mitigations

References