Cross-Cluster Privilege Escalation Vulnerability in Open Cluster Management by Red Hat
CVE-2026-4740
8.2HIGH
What is CVE-2026-4740?
A flaw exists in Open Cluster Management that compromises the security of Kubernetes client certificate renewal. This vulnerability allows a managed cluster administrator to create a forged client certificate capable of being validated by the OCM controller. As a result, this could enable an attacker to escalate privileges across clusters, potentially gaining unauthorized control over other managed clusters, including the central hub cluster.
References
CVSS V3.1
Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Arnaud FEVRIER (Orange) for reporting this issue.