Vulnerability in Red Hat Advanced Cluster Security for Kubernetes Affecting Deployment Metadata
CVE-2026-10079

8.5HIGH

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
31 July 2026

What is CVE-2026-10079?

A flaw exists in Red Hat Advanced Cluster Security for Kubernetes that allows a user with creation permissions to manipulate deployment metadata by setting the openshift.io/encoded-deployment-config label to 'null'. This manipulation results in the workload being treated as having no defined UID, name, or labels, and defaults the namespace to 'default'. Consequently, this breach of deployment metadata leads to the circumvention of policy detection and enforcement at deployment time, complicating compliance and accurate violation reporting for the affected deployment.

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was discovered by Moritz Clasmeier (Red Hat).
.