Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-4740

Опубликовано: 07 апр. 2026
Источник: nvd
CVSS3: 8.2
EPSS Низкий

Описание

A flaw was found in Open Cluster Management (OCM), the technology underlying Red Hat Advanced Cluster Management (ACM). Improper validation of Kubernetes client certificate renewal allows a managed cluster administrator to forge a client certificate that can be approved by the OCM controller. This enables cross-cluster privilege escalation and may allow an attacker to gain control over other managed clusters, including the hub cluster.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:redhat:advanced_cluster_management_for_kubernetes:-:*:*:*:*:*:*:*

EPSS

Процентиль: 2%
0.00112
Низкий

8.2 High

CVSS3

Дефекты

CWE-295
CWE-295

Связанные уязвимости

CVSS3: 8.2
redhat
4 месяца назад

A flaw was found in Open Cluster Management (OCM), the technology underlying Red Hat Advanced Cluster Management (ACM). Improper validation of Kubernetes client certificate renewal allows a managed cluster administrator to forge a client certificate that can be approved by the OCM controller. This enables cross-cluster privilege escalation and may allow an attacker to gain control over other managed clusters, including the hub cluster.

CVSS3: 8.2
github
4 месяца назад

Open Cluster Management (OCM): Cross-cluster privilege escalation via improper Kubernetes client certificate renewal validation

EPSS

Процентиль: 2%
0.00112
Низкий

8.2 High

CVSS3

Дефекты

CWE-295
CWE-295