CVE-2026-10079
Red Hat · Advanced Cluster Security for Kubernetes
A vulnerability in Red Hat Advanced Cluster Security for Kubernetes (RHACS) allows for insufficient verification of data authenticity.
Executive summary
A flaw in Red Hat Advanced Cluster Security for Kubernetes (RHACS) concerning data authenticity verification poses a high risk of integrity compromise.
Vulnerability
This vulnerability, identified as CWE-345, involves insufficient verification of data authenticity. It requires low-privileged authenticated access, allowing an attacker to manipulate data integrity within the cluster security environment.
Business impact
The CVSS score of 8.5 indicates a high-severity risk, particularly due to the potential for cross-domain integrity compromise. Successful exploitation could allow an attacker to bypass security controls or inject malicious configurations into the Kubernetes cluster. This poses a significant threat to the overall security posture of containerized infrastructure.
Remediation
Immediate Action: Consult the Red Hat Security Advisory (RHSA) for the specific patched version and apply the update immediately.
Proactive Monitoring: Monitor cluster audit logs for unauthorized configuration changes or unexpected data modifications in the security context.
Compensating Controls: Utilize Kubernetes network policies and admission controllers to restrict the impact of unauthorized data modifications while awaiting patch deployment.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Security teams should treat this vulnerability with high urgency. Users must verify their current version against the Red Hat advisory and apply the necessary patches to prevent potential integrity loss within their Kubernetes environments.