A flaw was found in Open Cluster Management (OCM), the technology underlying Red Hat Advanced Cluster Management (ACM). Improper validation of Kubernetes client certificate renewal allows a managed cluster administrator to forge a client certificate that can be approved by the OCM controller. This enables cross-cluster privilege escalation and may allow an attacker to gain control over other managed clusters, including the hub cluster.
References
Configurations
History
No history.
Information
Published : 2026-04-07 15:17
Updated : 2026-09-08 12:16
NVD link : CVE-2026-4740
Mitre link : CVE-2026-4740
CVE.ORG link : CVE-2026-4740
JSON object : View
Products Affected
redhat
- advanced_cluster_management_for_kubernetes
CWE
CWE-295
Improper Certificate Validation
