CVE-2026-93017
- EPSS -
- Veröffentlicht 08.10.2026 14:31:58
- Zuletzt bearbeitet 08.10.2026 15:17:56
The `insights-operator-gather` ClusterRole grants the operator's service account read access to secrets in the core API group with no namespace or resourceNames restriction — therefore, access to every secret in every namespace in the cluster. Ref: ...
CVE-2026-107176
- EPSS 0.16%
- Veröffentlicht 07.10.2026 19:29:31
- Zuletzt bearbeitet 07.10.2026 21:17:13
A flaw was found in the cluster-samples-operator. The RBAC Role coreos-pull-secret-reader in namespace openshift-config grants get, list, and watch permissions on all Secret resources without resourceNames scoping. The operator only requires access t...
CVE-2026-76061
- EPSS 0.23%
- Veröffentlicht 06.10.2026 19:24:30
- Zuletzt bearbeitet 07.10.2026 14:47:21
A flaw was found in CRI-O's `bind_mount_prefix` handling. When configured with a non-empty `bind_mount_prefix`, a malicious container or local attacker could use a Container Runtime Interface (CRI) hostPath containing an intermediate absolute symlink...
CVE-2026-83589
- EPSS 0.19%
- Veröffentlicht 01.10.2026 09:17:43
- Zuletzt bearbeitet 07.10.2026 00:17:21
A flaw was found in oauth-proxy. The application fails to properly validate the destination redirect parameter (`rd`) during post-login redirection. A remote attacker can exploit this vulnerability by enticing a user to follow a specially crafted lin...
CVE-2026-62146
- EPSS 0.11%
- Veröffentlicht 30.09.2026 11:49:20
- Zuletzt bearbeitet 30.09.2026 20:17:34
A trust-boundary flaw in CRI-O's sandbox state persistence allows attacker-influenced pod metadata to overwrite CRI-O's own reserved sandbox bookkeeping; once reloaded as trusted after a restart, a later container recreate in that sandbox can expose ...
CVE-2026-90462
- EPSS 0.21%
- Veröffentlicht 22.09.2026 15:50:00
- Zuletzt bearbeitet 07.10.2026 13:41:47
A flaw was found in SSSD. When configured with the LDAP access provider and `ldap_access_order` including `ppolicy` or `lockout`, a fail-open condition in the LDAP ppolicy access check can occur if a user lookup returns zero results. This can incorre...
- EPSS 0.31%
- Veröffentlicht 21.09.2026 08:15:45
- Zuletzt bearbeitet 22.09.2026 19:37:36
A vulnerability was found in CRI-O related to the container checkpoint and restore feature. When CRI-O is configured to restore containers from checkpoint archives, insufficient validation of restore metadata may allow a user with sufficient privileg...
CVE-2026-75885
- EPSS 0.41%
- Veröffentlicht 18.09.2026 21:58:11
- Zuletzt bearbeitet 08.10.2026 15:17:54
A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/devfile/samples/` endpoints allows a remote attacker to send crafted devfile payloads. This can lead to Server-Side Request Forgery (SSRF), where the c...
CVE-2026-90996
- EPSS 0.11%
- Veröffentlicht 14.09.2026 15:55:42
- Zuletzt bearbeitet 07.10.2026 14:29:19
A flaw was found in sssd. A local unprivileged user could send a specially crafted request with a zero-length body to the Network Security Services (NSS) responder. This could lead to a denial-of-service condition, causing the NSS responder to become...
- EPSS 0.11%
- Veröffentlicht 24.08.2026 21:22:49
- Zuletzt bearbeitet 28.08.2026 21:17:10
A flaw was found in CRI-O's container-creation environment-variable handling (`mergeEnvs` in `server/utils.go`, consumed by `setupContainerEnvironmentAndWorkdir` in `server/container_create.go`). When a `CreateContainer` request supplies a `nil` CRI ...