CVE-2026-16242
- EPSS 0.8%
- Veröffentlicht 20.07.2026 07:33:16
- Zuletzt bearbeitet 25.08.2026 05:17:20
A flaw was found in the Konnectivity proxy-server configuration for hosted control planes. The agent-facing listener was started without --cluster-ca-cert (and without token-based agent authentication), so client certificates were not validated. A re...
CVE-2026-10805
- EPSS 0.15%
- Veröffentlicht 04.06.2026 05:21:34
- Zuletzt bearbeitet 24.08.2026 09:16:44
A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkManager's dhclient backend when processing malformed Manufacturer Usage Description (MUD) URLs. A local user can exploit this flaw to escalate privileg...
CVE-2026-10101
- EPSS 0.18%
- Veröffentlicht 29.05.2026 16:16:24
- Zuletzt bearbeitet 21.07.2026 15:10:00
ACM/MCE assisted-service writes raw referenced pull-secret contents into `InfraEnv.status.conditions[].message` when pull-secret validation fails. A namespace principal with the stock `view` ClusterRole cannot directly read Secrets, but can read `Inf...
CVE-2026-7163
- EPSS 0.19%
- Veröffentlicht 30.04.2026 13:18:49
- Zuletzt bearbeitet 24.08.2026 13:19:19
A vulnerability in the assisted-service REST API, an optional Assisted Installer (assisted-service) component in the Multicluster Engine (MCE), allows an authenticated user with minimal namespace-scoped privileges to obtain administrative credentials...