CVE-2026-70496
- EPSS 0.26%
- Veröffentlicht 19.08.2026 18:16:13
- Zuletzt bearbeitet 27.08.2026 04:16:46
A flaw was found in search-v2-operator. The operator's ClusterRole has permissions equivalent to a cluster administrator, allowing it to impersonate other entities, write Role-Based Access Control (RBAC) configurations, approve Certificate Signing Re...
CVE-2026-66781
- EPSS 0.08%
- Veröffentlicht 18.08.2026 17:05:52
- Zuletzt bearbeitet 03.09.2026 13:06:00
A flaw was found in the Submariner operator. The Submariner Custom Resource (CR), used for configuring network connectivity, stores the IPsec pre-shared key (PSK) in an unencrypted format. This key, which is critical for securing communication betwee...
CVE-2026-75924
- EPSS 0.16%
- Veröffentlicht 18.08.2026 16:27:58
- Zuletzt bearbeitet 20.08.2026 13:08:53
A flaw was found in managed-serviceaccount. A compromised addon-manager pod, due to its ClusterRole granting excessive permissions, can read any secret across all namespaces. Additionally, it can approve arbitrary Certificate Signing Requests (CSRs),...
CVE-2026-66793
- EPSS 0.57%
- Veröffentlicht 18.08.2026 15:17:00
- Zuletzt bearbeitet 27.08.2026 04:16:46
A flaw was found in the governance-policy-addon-controller component of Red Hat Advanced Cluster Management for Kubernetes. A user with permissions to annotate the namespaced ManagedClusterAddOn resource can override the governance-policy container i...
CVE-2026-75485
- EPSS 0.14%
- Veröffentlicht 18.08.2026 15:15:42
- Zuletzt bearbeitet 05.09.2026 18:17:28
A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. The cluster Proxy object is dumped in raw form, bypassing the oc inspect redaction that would normally sanitize sensitive fields. This exposes proxy ...
CVE-2026-70495
- EPSS 0.1%
- Veröffentlicht 17.08.2026 19:28:37
- Zuletzt bearbeitet 27.08.2026 04:16:46
A flaw was found in search-v2-operator. This component's `search-serviceaccount` has overly broad permissions, allowing it to impersonate users and groups across the entire cluster. If an attacker gains access to any of the pods running under this se...
CVE-2026-71846
- EPSS 0.12%
- Veröffentlicht 12.08.2026 21:46:19
- Zuletzt bearbeitet 05.09.2026 18:17:28
A flaw was found in insights-client. The component's ServiceAccount is bound to a ClusterRole granting cluster-wide secrets get, list, and watch permissions, while the code only requires access to a single specific Secret. This excessive privilege me...
CVE-2026-71469
- EPSS 0.36%
- Veröffentlicht 12.08.2026 21:40:13
- Zuletzt bearbeitet 27.08.2026 04:16:47
A flaw was found in search-v2-api. An unauthenticated attacker can exploit this by sending requests with unique random bearer tokens. Each unique token creates a permanent entry in the unbounded tokenReviews cache, which is not properly cleared. This...
CVE-2026-71474
- EPSS 0.2%
- Veröffentlicht 11.08.2026 19:24:56
- Zuletzt bearbeitet 05.09.2026 18:17:28
A flaw was found in insights-client. When the application receives a non-200 response, it logs the request headers, which can include the cloud.openshift.com pull-secret token. A local user with access to pod logs on the hub could read this long-live...
CVE-2026-71475
- EPSS 0.28%
- Veröffentlicht 11.08.2026 19:24:18
- Zuletzt bearbeitet 05.09.2026 18:17:28
A flaw was found in insights-client. A compromised managed cluster, referred to as a 'spoke', can inject unencoded data into the Insights API URL path. This occurs because the ClusterID, which is controlled by the spoke, is used directly in the reque...