Authentication Bypass Vulnerability in MaaS API by Red Hat
CVE-2026-14450
9.9CRITICAL
What is CVE-2026-14450?
A vulnerability exists in the MaaS API that enables any pod within the Kubernetes cluster to circumvent the Kuadrant AuthPolicy gateway by manipulating HTTP headers, specifically X-MaaS-Username and X-MaaS-Group. This flaw allows attackers to gain unauthorized access and escalate privileges, leading to severe consequences such as the ability to create Kubernetes ServiceAccount tokens in other tenants' namespaces, revoke API keys, and exfiltrate sensitive access configurations.