CVE-2026-70496
- EPSS 0.26%
- Veröffentlicht 19.08.2026 18:16:13
- Zuletzt bearbeitet 20.08.2026 13:08:53
A flaw was found in search-v2-operator. The operator's ClusterRole has permissions equivalent to a cluster administrator, allowing it to impersonate other entities, write Role-Based Access Control (RBAC) configurations, approve Certificate Signing Re...
CVE-2026-66781
- EPSS 0.08%
- Veröffentlicht 18.08.2026 17:05:52
- Zuletzt bearbeitet 20.08.2026 13:08:53
A flaw was found in the Submariner operator. The Submariner Custom Resource (CR), used for configuring network connectivity, stores the IPsec pre-shared key (PSK) in an unencrypted format. This key, which is critical for securing communication betwee...
CVE-2026-75924
- EPSS 0.16%
- Veröffentlicht 18.08.2026 16:27:58
- Zuletzt bearbeitet 20.08.2026 13:08:53
A flaw was found in managed-serviceaccount. A compromised addon-manager pod, due to its ClusterRole granting excessive permissions, can read any secret across all namespaces. Additionally, it can approve arbitrary Certificate Signing Requests (CSRs),...
CVE-2026-66793
- EPSS 0.57%
- Veröffentlicht 18.08.2026 15:17:00
- Zuletzt bearbeitet 20.08.2026 13:08:53
A flaw was found in the governance-policy-addon-controller component of Red Hat Advanced Cluster Management for Kubernetes. A user with permissions to annotate the namespaced ManagedClusterAddOn resource can override the governance-policy container i...
CVE-2026-75485
- EPSS 0.14%
- Veröffentlicht 18.08.2026 15:15:42
- Zuletzt bearbeitet 20.08.2026 13:08:53
A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. The cluster Proxy object is dumped in raw form, bypassing the oc inspect redaction that would normally sanitize sensitive fields. This exposes proxy ...
CVE-2026-70495
- EPSS 0.1%
- Veröffentlicht 17.08.2026 19:28:37
- Zuletzt bearbeitet 18.08.2026 15:04:46
A flaw was found in search-v2-operator. This component's `search-serviceaccount` has overly broad permissions, allowing it to impersonate users and groups across the entire cluster. If an attacker gains access to any of the pods running under this se...
CVE-2026-71469
- EPSS 0.36%
- Veröffentlicht 12.08.2026 21:40:13
- Zuletzt bearbeitet 14.08.2026 23:16:32
A flaw was found in search-v2-api. An unauthenticated attacker can exploit this by sending requests with unique random bearer tokens. Each unique token creates a permanent entry in the unbounded tokenReviews cache, which is not properly cleared. This...
- EPSS 0.25%
- Veröffentlicht 05.08.2026 09:18:14
- Zuletzt bearbeitet 12.08.2026 22:17:13
A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM). A user with namespace-scoped "edit" privileges in an ACM hub namespace can create a Channel...
CVE-2026-17107
- EPSS 0.35%
- Veröffentlicht 24.07.2026 18:56:05
- Zuletzt bearbeitet 19.08.2026 00:16:26
A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests without first re...
CVE-2026-44495
- EPSS 0.78%
- Veröffentlicht 11.06.2026 15:33:12
- Zuletzt bearbeitet 20.08.2026 13:18:47
Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process has already po...