Kubernetes Certificates Vulnerability in cert-manager
CVE-2026-62290

7.3HIGH

Key Information:

Vendor
CVE Published:
16 July 2026

What is CVE-2026-62290?

A vulnerability in the cert-manager allows namespace users to create Challenge resources without proper admission validation. This enables potential attackers to set Challenge.spec.solver values that reference a ClusterIssuer, bypassing important DNS settings. As a result, they could manipulate the cert-manager to utilize DNS credentials for unauthorized provider settings, leading to possible exposure of sensitive values like X-Api-User and X-Api-Key for acme-dns. This issue has been resolved in cert-manager versions 1.19.6 and 1.20.3.

Affected Version(s)

cert-manager >= 1.18.0, < 1.19.6 < 1.18.0, 1.19.6

cert-manager >= 1.20.0, < 1.20.3 < 1.20.0, 1.20.3

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.