← Zurück zur CVE-Suche

CVE-2026-10079

Red Hat Advanced Cluster Security

Beschreibung

A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubernetes Deployments, ACS replaces deployment identity metadata based on the openshift.io/encoded-deployment-config label. A user with permission to create Deployments can set this label to -null-, causing ACS to treat the workload as having empty UID, name and labels and namespace -default-. This bypasses deploy-time policy detection and enforcement visibility, prevents correct persistence in Central and breaks violation reporting and compliance correlation for the affected deployment.

CVSS 8.5EPSS 0.165%Risiko 0.86
Quelle öffnen
Veröffentlicht
2026-07-31 10:16:43
Betroffene Versionen
unknown
Typ
Kritische Software
Zuletzt geändert
2026-08-03 16:39:02
Vektor
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N