CVE-2026-4740

EUVD-2026-19690
A flaw was found in Open Cluster Management (OCM), the technology underlying Red Hat Advanced Cluster Management (ACM). Improper validation of Kubernetes client certificate renewal allows a managed cluster administrator to forge a client certificate that can be approved by the OCM controller. This enables cross-cluster privilege escalation and may allow an attacker to gain control over other managed clusters, including the hub cluster.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.2 HIGH
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 4.58%
Affected Products (NVD)
VendorProductVersion
redhatadvanced_cluster_management_for_kubernetes
-
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
Red Hatmulticluster engine for Kubernetes 2.10
1776881164 ≤
𝑥
< *
ADP
Red Hatmulticluster engine for Kubernetes 2.11
1777478390 ≤
𝑥
< *
ADP
Red Hatmulticluster engine for Kubernetes 2.6
1775977180 ≤
𝑥
< *
ADP
Red Hatmulticluster engine for Kubernetes 2.8
1775638726 ≤
𝑥
< *
ADP
Red Hatmulticluster engine for Kubernetes 2.9
1776445095 ≤
𝑥
< *
ADP