Description
A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubernetes Deployments, ACS replaces deployment identity metadata based on the openshift.io/encoded-deployment-config label. A user with permission to create Deployments can set this label to -null-, causing ACS to treat the workload as having empty UID, name and labels and namespace -default-. This bypasses deploy-time policy detection and enforcement visibility, prevents correct persistence in Central and breaks violation reporting and compliance correlation for the affected deployment.
CVSS 8.5EPSS 0.165%Risk 0.86
View source- Published
- 2026-07-31 10:16:43
- Affected versions
- unknown
- Type
- Critical software
- Last modified
- 2026-08-03 16:39:02
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N