Cross-Cluster Privilege Escalation Vulnerability in Open Cluster Management by Red Hat
CVE-2026-4740

8.2HIGH

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
7 April 2026

What is CVE-2026-4740?

A flaw exists in Open Cluster Management that compromises the security of Kubernetes client certificate renewal. This vulnerability allows a managed cluster administrator to create a forged client certificate capable of being validated by the OCM controller. As a result, this could enable an attacker to escalate privileges across clusters, potentially gaining unauthorized control over other managed clusters, including the central hub cluster.

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Arnaud FEVRIER (Orange) for reporting this issue.
.