Cross-Cluster Privilege Escalation Vulnerability in Open Cluster Management by Red Hat
CVE-2026-4740
8.2HIGH
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 7 April 2026
What is CVE-2026-4740?
A flaw exists in Open Cluster Management that compromises the security of Kubernetes client certificate renewal. This vulnerability allows a managed cluster administrator to create a forged client certificate capable of being validated by the OCM controller. As a result, this could enable an attacker to escalate privileges across clusters, potentially gaining unauthorized control over other managed clusters, including the central hub cluster.
Affected Version(s)
multicluster engine for Kubernetes 2.1 1776881164
multicluster engine for Kubernetes 2.11 1777478390
multicluster engine for Kubernetes 2.6 1775977180
References
CVSS V3.1
Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Arnaud FEVRIER (Orange) for reporting this issue.