Privilege Escalation Vulnerability in OpenShift Pipelines Operator by Red Hat
CVE-2026-10840

7.1HIGH

What is CVE-2026-10840?

A vulnerability in the OpenShift Pipelines operator permits authenticated users to gain unauthorized access to sensitive resources. Specifically, the tekton-scheduler-rolebinding ClusterRoleBinding grants the system:authenticated group write permissions to Kueue and cert-manager custom resources. This oversight can allow any authenticated user to compromise workload scheduling, manipulate scheduling priorities, delete other users' Workload objects, and potentially modify TLS Secrets, including the default ingress controller certificate, leading to significant security risks.

Affected Version(s)

Red Hat OpenShift Builds 1.7.4 1783341609

Red Hat OpenShift Builds 1.8.0 1784121108

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Christopher Lusk (North Echo Security Research) for reporting this issue.
.