← Späť na vyhľadávanie CVE

CVE-2026-10079

Red Hat Advanced Cluster Security

Popis

A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubernetes Deployments, ACS replaces deployment identity metadata based on the openshift.io/encoded-deployment-config label. A user with permission to create Deployments can set this label to -null-, causing ACS to treat the workload as having empty UID, name and labels and namespace -default-. This bypasses deploy-time policy detection and enforcement visibility, prevents correct persistence in Central and breaks violation reporting and compliance correlation for the affected deployment.

CVSS 8.5EPSS 0.165%Riziko 0.86
Zobraziť zdroj
Zverejnené
2026-07-31 10:16:43
Dotknuté verzie
unknown
Typ
Kritický softvér
Posledná úprava
2026-08-03 16:39:02
Vektor
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N