Cross-Cluster Privilege Escalation Vulnerability in Open Cluster Management by Red Hat
CVE-2026-4740

8.2HIGH

What is CVE-2026-4740?

A flaw exists in Open Cluster Management that compromises the security of Kubernetes client certificate renewal. This vulnerability allows a managed cluster administrator to create a forged client certificate capable of being validated by the OCM controller. As a result, this could enable an attacker to escalate privileges across clusters, potentially gaining unauthorized control over other managed clusters, including the central hub cluster.

Affected Version(s)

multicluster engine for Kubernetes 2.1 1776881164

multicluster engine for Kubernetes 2.11 1777478390

multicluster engine for Kubernetes 2.6 1775977180

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Arnaud FEVRIER (Orange) for reporting this issue.
.