Vulnerability in Red Hat Advanced Cluster Security for Kubernetes Affecting Deployment Metadata
CVE-2026-10079
8.5HIGH
What is CVE-2026-10079?
A flaw exists in Red Hat Advanced Cluster Security for Kubernetes that allows a user with creation permissions to manipulate deployment metadata by setting the openshift.io/encoded-deployment-config label to 'null'. This manipulation results in the workload being treated as having no defined UID, name, or labels, and defaults the namespace to 'default'. Consequently, this breach of deployment metadata leads to the circumvention of policy detection and enforcement at deployment time, complicating compliance and accurate violation reporting for the affected deployment.
References
CVSS V3.1
Score:
8.5
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This issue was discovered by Moritz Clasmeier (Red Hat).