Kubernetes Certificates Vulnerability in cert-manager
CVE-2026-62290
7.3HIGH
What is CVE-2026-62290?
A vulnerability in the cert-manager allows namespace users to create Challenge resources without proper admission validation. This enables potential attackers to set Challenge.spec.solver values that reference a ClusterIssuer, bypassing important DNS settings. As a result, they could manipulate the cert-manager to utilize DNS credentials for unauthorized provider settings, leading to possible exposure of sensitive values like X-Api-User and X-Api-Key for acme-dns. This issue has been resolved in cert-manager versions 1.19.6 and 1.20.3.
Affected Version(s)
cert-manager >= 1.18.0, < 1.19.6 < 1.18.0, 1.19.6
cert-manager >= 1.20.0, < 1.20.3 < 1.20.0, 1.20.3
